ZeroHour

CVE-2026-82302

large

Incorrect Authorization in Kibana Allows Unauthorized Configuration Changes

CVSS 3.1
8.1 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Kibana, Elastic's management and visualization interface for Elasticsearch, contains an incorrect authorization flaw (CWE-863) that allows unauthorized modification of its configuration. An attacker who already holds a low-privileged account can trigger the flaw over the network, without user interaction, by exploiting incorrectly configured access control security levels (CAPEC-180). Successful exploitation carries high integrity (and per the CVSS 3.1 score, high confidentiality) impact, letting the attacker alter Kibana configuration without proper authorization. Any organization running an affected Kibana deployment in which access-control security levels are misconfigured is exposed, though the source data does not specify affected version ranges. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known, and EPSS estimates only about a 0.2% chance of exploitation within the next 30 days.

What to do: Track Elastic's advisory for CVE-2026-82302 and upgrade Kibana to the patched release as soon as fixed versions are published, since version details are not included in the available data. In the meantime, review Kibana's access-control and security-level configuration for misconfigurations, confirm low-privileged users cannot write to configuration, and restrict internet exposure of Kibana endpoints. Although no exploitation is known, audit accounts and logs for unexpected configuration changes.

Affected
Elastic Kibana
Estimated exposure
largelikely tens of thousands of internet-exposed Kibana instances, with a much larger overall install base — Kibana ships by default with Elasticsearch, one of the most widely deployed search and log-analytics platforms, and public internet scans routinely index tens of thousands of exposed Kibana instances; actual exploitability is narrower…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.