Executive brief
Kibana, a data visualization and analytics platform used with Elasticsearch, contains a missing authorization flaw that allows authenticated users with minimal privileges to bypass access controls. An attacker with a low-privileged Elasticsearch account could view sensitive Fleet deployment metadata that should be restricted, potentially exposing infrastructure configuration details and deployment information.
Technical details
The vulnerability is a missing authorization (CWE-862) flaw in Kibana's space access control and feature authorization logic. An authenticated user with minimal Elasticsearch privileges can bypass authorization checks to access Fleet deployment metadata from the default Kibana space. The attack requires network access and prior authentication to Elasticsearch, with no user interaction needed. The vulnerability affects Kibana 9.x versions from 9.0.0 through 9.4.5 and version 9.5.0, requiring native agentless connector infrastructure and active Fleet policies to be configured. The flaw is resolved in Kibana versions 9.4.6 and 9.5.1; no workarounds are available for earlier versions.
Affected products
- Elastic Kibana 9.0.0 to 9.4.5, 9.5.0
Timeline
- 2026-09-01: disclosed: CVE-2026-78603 published
- 2026-09-01: patched: Fixed in Kibana 9.4.6 and 9.5.1