Junglewise Threat Intelligence

CVE-2026-78596: Elastic Kibana authorization bypass in Entity Analytics migration

CVE-2026-78596 · Severity: medium · CVSS 4.3 · Published 2026-09-03

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is Elastic's visualization and analytics platform used to explore and visualize security and business data. A missing authorization check allows authenticated users with read-only access in one workspace to perform privileged write operations across all workspaces through the Entity Analytics feature, potentially leading to unauthorized data modification and exposure of sensitive analytics across the organization.

Technical details

This vulnerability is a missing authorization check (CWE-862) in Kibana's Entity Analytics migration operations. An authenticated user holding Security read-level access in a single Kibana space can trigger migration operations that should require elevated privileges, but instead perform privileged writes across all spaces without proper authorization validation. The attack is network-accessible and requires only valid authentication credentials with limited scope; no user interaction is required. An attacker can modify data and configurations across multi-space deployments, bypassing intended access controls. The vulnerability has been patched in Kibana versions 8.19.21, 9.4.6, and 9.5.3, with no workarounds available for unpatched systems.

Affected products

  • Elastic Kibana 8.18.3 through 8.19.20, 9.0.3 through 9.4.5, 9.5.0 through 9.5.2

Timeline

  • 2026-09-03: disclosed: Security advisory ESA-2026-154 published
  • 2026-09-03: patched: Fixed in versions 8.19.21, 9.4.6, 9.5.3

References

Related threats