CVE-2026-78583
largeIncorrect Authorization in Elastic Kibana Grants Over-Privileged Agent Credentials
Kibana contains an incorrect authorization flaw (CWE-863) in which Elasticsearch cluster privilege declarations supplied by integration packages are not validated before being used to mint credentials for enrolled Elastic Agents. A user who holds Fleet management privileges can manipulate these privilege declarations (CAPEC-153, input data manipulation) so that every Elastic Agent assigned to a targeted policy receives a credential with arbitrarily elevated Elasticsearch cluster privileges, potentially up to full cluster administration. An attacker with this level of access gains high confidentiality and integrity impact (CVSS 3.1: 8.1, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N), since the mis-issued agent credentials can be used to access or modify cluster data broadly. Affected users are organizations running Elastic Kibana with Fleet management and enrolled Elastic Agents that use integration packages; specific affected and patched version ranges are not provided in the available data. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Upgrade Kibana to a patched release per Elastic's advisory (specific fixed versions are not stated in the available data). Restrict Fleet management privileges to trusted users, and review integration packages for overly broad Elasticsearch cluster privilege declarations. Audit credentials issued to enrolled Elastic Agents for unexpected cluster privileges and re-issue/rotate agent credentials if abuse is suspected.
| Elastic Kibana | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.
- Vendors
- elastic
- Products
- kibana
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.