PT-2026-85211 · Elastic · Kibana+2

CVE-2026-78583

·

Published

2026-09-03

·

Updated

2026-09-09

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kibana versions 8.0.0 through 8.19.20 Kibana versions 9.0.0 through 9.4.5 Kibana versions 9.5.0 through 9.5.2
Description Incorrect authorization in Kibana allows for privilege escalation through input data manipulation. The system fails to validate Elasticsearch cluster privilege declarations originating from integration packages before using them to mint credentials for enrolled Elastic Agents. Consequently, a user with Fleet management privileges can cause every Elastic Agent on a targeted policy to receive credentials with arbitrarily elevated Elasticsearch cluster privileges, potentially granting full cluster administration.
Recommendations Upgrade Kibana versions 8.0.0 through 8.19.20 to 8.19.21 or later. Upgrade Kibana versions 9.0.0 through 9.4.5 to 9.4.6 or later. Upgrade Kibana versions 9.5.0 through 9.5.2 to 9.5.3 or later.

Exploit

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-78583
BIT-KIBANA-2026-78583
CVE-2026-78583

Affected Products

Agent
Elasticsearch
Kibana