Junglewise Threat Intelligence

CVE-2026-78593: Elastic Kibana code injection in Cribl integration

CVE-2026-78593 · Severity: medium · CVSS 4.3 · Published 2026-09-03

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a widely-used analytics and visualization platform, contains a vulnerability in its Cribl data integration that allows authenticated administrators with Fleet management privileges to inject malicious code. An attacker with these privileges can manipulate Elasticsearch ingest pipeline configurations beyond their authorized permissions, potentially modifying how data flows through the system and affecting data integrity across the deployment.

Technical details

The vulnerability is a code injection flaw (CWE-94) in Kibana's Cribl integration caused by insufficient validation of a configuration field. An authenticated user holding Fleet management privileges (fleet:all) can inject attacker-controlled expressions into a server-side script template, leading to arbitrary modification of Elasticsearch ingest pipelines with escalated privileges. The attack requires valid Kibana authentication and the Fleet management role; no user interaction or special configuration beyond having the Cribl integration installed is needed. An attacker can write ingest pipelines beyond their authorized Elasticsearch permissions, potentially altering data processing rules. The vulnerability is fixed in Kibana versions 8.19.21, 9.4.6, and 9.5.3.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.20, 9.0.0 to 9.4.5, 9.5.0 to 9.5.2

Timeline

  • 2026-09-03: disclosed: CVE-2026-78593 public disclosure
  • 2026-09-03: patched: Fixed in Kibana 8.19.21, 9.4.6, 9.5.3

References

Related threats