Junglewise Threat Intelligence

CVE-2026-78581: Elastic Kibana authorization bypass in AI Assistant

CVE-2026-78581 · Severity: medium · CVSS 4.2 · Published 2026-08-25

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a web-based visualization and analytics platform used to explore and analyze data from Elasticsearch. An authenticated user with access to the AI Assistant feature can bypass access controls to view or modify another user's AI conversation by referencing its identifier, potentially exposing sensitive analysis or chat history that should remain private.

Technical details

This vulnerability is an authorization bypass (CWE-639) affecting Kibana's AI Assistant feature where conversation identifiers are not properly validated against the requesting user's access rights. An authenticated attacker with AI Assistant access can craft a request using another user's conversation identifier to access or modify conversations they do not own. The attack requires knowledge of the target conversation's identifier and network access to Kibana, but does not require elevated privileges. The vulnerability is resolved in Kibana versions 8.16.3 and 8.17.2; affected versions include 8.0.0 through 8.16.2 and 8.17.0 through 8.17.1.

Affected products

  • Elastic Kibana 8.0.0 through 8.16.2, 8.17.0 through 8.17.1

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in versions 8.16.3 and 8.17.2

References

Related threats