CVE-2026-78582

Summary

Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.

Affected Software

VendorProductVersion RangeStatus
ElasticKibana7.12.0 <= 7.17.29affected
ElasticKibana8.0.0 <= 8.19.21affected
ElasticKibana9.0.0 <= 9.4.6affected
ElasticKibana9.5.0 <= 9.5.2affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References