PT-2026-85211 · Elastic · Kibana+2
CVE-2026-78583
·
Published
2026-09-03
·
Updated
2026-09-09
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kibana versions 8.0.0 through 8.19.20
Kibana versions 9.0.0 through 9.4.5
Kibana versions 9.5.0 through 9.5.2
Description
Incorrect authorization in Kibana allows for privilege escalation through input data manipulation. The system fails to validate Elasticsearch cluster privilege declarations originating from integration packages before using them to mint credentials for enrolled Elastic Agents. Consequently, a user with Fleet management privileges can cause every Elastic Agent on a targeted policy to receive credentials with arbitrarily elevated Elasticsearch cluster privileges, potentially granting full cluster administration.
Recommendations
Upgrade Kibana versions 8.0.0 through 8.19.20 to 8.19.21 or later.
Upgrade Kibana versions 9.0.0 through 9.4.5 to 9.4.6 or later.
Upgrade Kibana versions 9.5.0 through 9.5.2 to 9.5.3 or later.
Exploit
Fix
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agent
Elasticsearch
Kibana