Executive brief
Kibana, Elastic's popular data visualization and analytics platform, contains an authorization flaw in its Workflows feature that allows users with editing permissions to trigger scheduled tasks with higher-privileged account credentials. This enables attackers with limited access to view, modify, or steal sensitive data they would normally be blocked from accessing.
Technical details
This is an incorrect authorization vulnerability (CWE-863) in Kibana's Workflows feature, introduced in version 9.3.0. A user with workflow edit permissions can cause scheduled workflow executions to run under a different, higher-privileged user's context, bypassing access control checks. The vulnerability requires network access and authenticated user credentials, but no additional user interaction. An attacker can exploit this to access and modify data beyond their authorization scope. The issue is fixed in Kibana 9.4.3; no workarounds are available for affected versions.
Affected products
- Elastic Kibana 9.3.0 through 9.4.2
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in Kibana 9.4.3