
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78601 is a Missing Authorization vulnerability (CWE-862) in Elastic Kibana's Entity Store component that can lead to information disclosure via Privilege Abuse (CAPEC-122). It affects Kibana versions 9.4.0 through 9.4.4, with version 9.4.5 containing the fix. The vulnerability was published on September 2, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is a missing authorization check (CWE-862) on a Kibana Entity Store configuration operation. An authenticated user with elevated Kibana privileges can manipulate this configuration to indirectly trigger a background task that reads from Elasticsearch indices the user is not authorized to access. The derived entity data processed by that background task is subsequently exposed through the Entity Store output, effectively bypassing index-level access controls without directly querying the restricted indices. No public proof-of-concept or technical write-up beyond the vendor advisory is currently available (GitHub Advisory, Elastic Advisory).
Successful exploitation results in unauthorized read access to Elasticsearch indices, exposing derived entity data that the attacker should not be able to view — a high confidentiality impact. There is also a low integrity impact, as the attacker can influence Entity Store configuration. Availability is not affected. The scope is limited to the affected Kibana/Elasticsearch deployment, but sensitive security or operational data stored in restricted indices could be disclosed to a privileged-but-unauthorized user (GitHub Advisory).
There is no evidence of in-the-wild exploitation or a public proof-of-concept at this time. Exploitation requires an authenticated session with elevated Kibana privileges, significantly limiting the attacker pool. The EPSS score is approximately 0.19–0.21%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" and automation as "no" (GitHub Advisory, Elastic Advisory).
Elastic has released Kibana 9.4.5 to address this vulnerability; organizations running versions 9.4.0 through 9.4.4 should upgrade immediately. As interim mitigations, restrict elevated Kibana privileges to only users who genuinely require them, and audit existing Entity Store configurations for unauthorized index access patterns. Monitor Entity Store outputs for unexpected data exposure from indices that should be restricted (Elastic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."