ZeroHour

CVE-2026-78583

large

Incorrect Authorization in Elastic Kibana Grants Over-Privileged Agent Credentials

CVSS 3.1
8.1 high
EPSS
<1%p13
Published
()
Modified
AI analysis

Kibana contains an incorrect authorization flaw (CWE-863) in which Elasticsearch cluster privilege declarations supplied by integration packages are not validated before being used to mint credentials for enrolled Elastic Agents. A user who holds Fleet management privileges can manipulate these privilege declarations (CAPEC-153, input data manipulation) so that every Elastic Agent assigned to a targeted policy receives a credential with arbitrarily elevated Elasticsearch cluster privileges, potentially up to full cluster administration. An attacker with this level of access gains high confidentiality and integrity impact (CVSS 3.1: 8.1, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N), since the mis-issued agent credentials can be used to access or modify cluster data broadly. Affected users are organizations running Elastic Kibana with Fleet management and enrolled Elastic Agents that use integration packages; specific affected and patched version ranges are not provided in the available data. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Upgrade Kibana to a patched release per Elastic's advisory (specific fixed versions are not stated in the available data). Restrict Fleet management privileges to trusted users, and review integration packages for overly broad Elasticsearch cluster privilege declarations. Audit credentials issued to enrolled Elastic Agents for unexpected cluster privileges and re-issue/rotate agent credentials if abuse is suspected.

Affected
Elastic Kibana
Estimated exposure
largetens of thousands of Fleet-enabled Kibana deployments (Elastic Agent/Fleet is the current default agent stack across Elastic's large install base) — Elastic is deployed at hundreds of thousands of organizations and public internet scans historically show tens of thousands of Kibana instances; only the subset running Fleet with enrolled Elastic Agents and integration packages is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.

Vendors
elastic
Products
kibana
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.