
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-82299 is an Incorrect Authorization vulnerability (CWE-863) in Elastic Kibana that can lead to information disclosure via exploitation of incorrectly configured access control security levels (CAPEC-180). It affects Kibana versions 9.0.0 through 9.4.5 and 9.5.0 through 9.5.2, with fixed versions released on September 3, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is Incorrect Authorization (CWE-863), where Kibana does not correctly perform authorization checks when an authenticated user attempts to access a resource or perform an action. This allows a low-privileged, network-accessible attacker to bypass access control security levels and reach data or functionality beyond their intended permissions. The attack vector is network-based, requires low privileges and no user interaction, and exploits improperly configured role-based access control (RBAC) mechanisms within Kibana (GitHub Advisory, Elastic Advisory).
Successful exploitation results in high confidentiality impact, allowing a low-privileged authenticated user to access sensitive information they are not authorized to view within Kibana. There is no integrity or availability impact. Depending on the data indexed in the associated Elasticsearch cluster, exposed information could include logs, metrics, security events, or other sensitive organizational data (GitHub Advisory, Elastic Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.20%, indicating a low near-term probability of exploitation. Exploitation is not automatable per NVD SSVC assessment, as it requires an authenticated low-privileged user (Elastic Advisory).
Elastic released patched versions Kibana 9.4.6 and 9.5.3 on September 3, 2026, addressing this vulnerability. Users should upgrade to one of these versions immediately. As interim measures, administrators should audit and verify RBAC configurations in Kibana, restrict network access to Kibana instances to authorized users and networks only, and monitor Kibana logs for unauthorized access attempts or anomalous data access patterns (Elastic Advisory, GitHub Advisory).
The vulnerability was assigned by Elastic and disclosed via the Elastic security discussion forum alongside the patched release. Coverage has been limited to standard vulnerability aggregation platforms such as VulDB, CVEFeed, and OSV, with no notable independent researcher commentary or significant social media discussion observed at this time (Elastic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."