Junglewise Threat Intelligence

CVE-2026-78583: Elastic Kibana privilege escalation via Fleet integration validation bypass

CVE-2026-78583 · Severity: high · CVSS 8.1 · Published 2026-09-03

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana's Fleet feature, which manages and deploys monitoring agents across infrastructure, fails to validate privilege declarations from integration packages. An attacker with Fleet management privileges can craft malicious integration configurations to grant enrolled Elastic Agents arbitrarily high privileges, including full cluster administration, affecting all agents controlled by a targeted policy.

Technical details

This is an authorization bypass vulnerability (CWE-863) in Kibana's Fleet agent management system. The root cause is insufficient validation of Elasticsearch cluster privilege declarations originating from integration packages before these privileges are used to mint credentials for enrolled Elastic Agents. An authenticated attacker with Fleet management privileges can manipulate integration package data to inject elevated privilege claims that are trusted without validation. The attack requires both Fleet integration management and agent policy management privileges held simultaneously. Successful exploitation results in arbitrary privilege escalation up to and including full Elasticsearch cluster administration on all agents in the targeted policy. The vulnerability is patched in Kibana 8.19.21, 9.4.6, and 9.5.3.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.20, 9.0.0 to 9.4.5, 9.5.0 to 9.5.2

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Fixed in Kibana 8.19.21, 9.4.6, and 9.5.3

References

Related threats