CVE-2026-78601
Kibana vulnerability analysis and mitigation

Overview

CVE-2026-78601 is a Missing Authorization vulnerability (CWE-862) in Elastic Kibana's Entity Store component that can lead to information disclosure via Privilege Abuse (CAPEC-122). It affects Kibana versions 9.4.0 through 9.4.4, with version 9.4.5 containing the fix. The vulnerability was published on September 2, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Elastic Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) on a Kibana Entity Store configuration operation. An authenticated user with elevated Kibana privileges can manipulate this configuration to indirectly trigger a background task that reads from Elasticsearch indices the user is not authorized to access. The derived entity data processed by that background task is subsequently exposed through the Entity Store output, effectively bypassing index-level access controls without directly querying the restricted indices. No public proof-of-concept or technical write-up beyond the vendor advisory is currently available (GitHub Advisory, Elastic Advisory).

Impact

Successful exploitation results in unauthorized read access to Elasticsearch indices, exposing derived entity data that the attacker should not be able to view — a high confidentiality impact. There is also a low integrity impact, as the attacker can influence Entity Store configuration. Availability is not affected. The scope is limited to the affected Kibana/Elasticsearch deployment, but sensitive security or operational data stored in restricted indices could be disclosed to a privileged-but-unauthorized user (GitHub Advisory).

Exploitability

There is no evidence of in-the-wild exploitation or a public proof-of-concept at this time. Exploitation requires an authenticated session with elevated Kibana privileges, significantly limiting the attacker pool. The EPSS score is approximately 0.19–0.21%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" and automation as "no" (GitHub Advisory, Elastic Advisory).

Mitigation and workarounds

Elastic has released Kibana 9.4.5 to address this vulnerability; organizations running versions 9.4.0 through 9.4.4 should upgrade immediately. As interim mitigations, restrict elevated Kibana privileges to only users who genuinely require them, and audit existing Entity Store configurations for unauthorized index access patterns. Monitor Entity Store outputs for unexpected data exposure from indices that should be restricted (Elastic Advisory).

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-82302HIGH8.1
  • Kibana logoKibana
  • kibana-8.19
NoYesSep 03, 2026
CVE-2026-82299MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.4
NoYesSep 03, 2026
CVE-2026-82298MEDIUM4.3
  • Kibana logoKibana
  • kibana-9.5
NoYesSep 03, 2026
CVE-2026-78596MEDIUM4.3
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesSep 03, 2026
CVE-2026-78595MEDIUM4.3
  • Kibana logoKibana
  • kibana-9.5
NoYesSep 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management