CVE-2026-82302
largeIncorrect Authorization in Kibana Allows Unauthorized Configuration Changes
Kibana, Elastic's management and visualization interface for Elasticsearch, contains an incorrect authorization flaw (CWE-863) that allows unauthorized modification of its configuration. An attacker who already holds a low-privileged account can trigger the flaw over the network, without user interaction, by exploiting incorrectly configured access control security levels (CAPEC-180). Successful exploitation carries high integrity (and per the CVSS 3.1 score, high confidentiality) impact, letting the attacker alter Kibana configuration without proper authorization. Any organization running an affected Kibana deployment in which access-control security levels are misconfigured is exposed, though the source data does not specify affected version ranges. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known, and EPSS estimates only about a 0.2% chance of exploitation within the next 30 days.
What to do: Track Elastic's advisory for CVE-2026-82302 and upgrade Kibana to the patched release as soon as fixed versions are published, since version details are not included in the available data. In the meantime, review Kibana's access-control and security-level configuration for misconfigurations, confirm low-privileged users cannot write to configuration, and restrict internet exposure of Kibana endpoints. Although no exploitation is known, audit accounts and logs for unexpected configuration changes.
| Elastic Kibana | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.