
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78596 is a Missing Authorization vulnerability (CWE-862) in Elastic Kibana that allows authenticated users with limited privileges to perform unauthorized data modifications. An authenticated user holding Security read-level access in a single Kibana space can trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, exceeding their intended access scope. Affected versions include Kibana 8.18.3–8.19.20, 9.0.3–9.4.5, and 9.5.0–9.5.2. It was published on September 3, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is a missing authorization check (CWE-862) in Kibana's Entity Analytics migration operations, exploitable via Privilege Abuse (CAPEC-122). When a user with Security read-level access in one Kibana space initiates an Entity Analytics migration, the application fails to verify whether that user has write permissions across all Kibana spaces before executing the operation. This allows the migration routine to perform privileged writes beyond the user's authorized scope, effectively bypassing Kibana's space-based access control model. No public proof-of-concept code has been identified (GitHub Advisory, Elastic Advisory).
Successful exploitation allows an authenticated attacker with minimal privileges (Security read-level in a single space) to modify data across all Kibana spaces without authorization. The primary impact is on data integrity — confidentiality and availability are not directly affected. In environments where multiple teams or tenants share a Kibana deployment with space-based isolation, this vulnerability could allow a low-privileged user to corrupt or tamper with Entity Analytics data belonging to other spaces, undermining the integrity of security analytics workflows (GitHub Advisory, Elastic Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-78596. The EPSS score is approximately 0.152%, indicating a low probability of exploitation in the near term. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for authenticated access and manual triggering of migration operations. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Elastic Advisory).
Elastic has released patched versions addressing this vulnerability: Kibana 8.19.21, 9.4.6, and 9.5.3. Users should upgrade to one of these fixed versions as the primary remediation. As an interim measure, administrators should review and audit Kibana user roles, ensuring that users with Security read-level access are limited to the minimum necessary permissions, and monitor for unexpected Entity Analytics migration activity. Restricting access to Entity Analytics migration operations to only highly privileged users can reduce exposure until patching is complete (Elastic Advisory, GitHub Advisory).
Elastic published an official security advisory (ESA-2026-154) disclosing the vulnerability and providing patched versions on September 3, 2026. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (Elastic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."