Executive brief
Kibana, a data analytics and visualization platform used by enterprises to monitor and analyze logs and metrics, contains an authorization flaw in its AI Assistant feature. When multiple authentication systems are in use and two different users happen to have the same username in different systems, one user could view, modify, or delete the other user's private AI Assistant knowledge entries, exposing sensitive data and potentially disrupting operations.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in Kibana's Elastic AI Assistant that fails to properly constrain access based on ACLs when authenticating users across multiple authentication realms. The root cause stems from the system using only the username for access control without considering the authentication realm, allowing users from different realms with identical usernames to access each other's private Knowledge Base entries. Attack requires an authenticated user who shares a username with another user in a different authentication realm, plus access to the AI Assistant feature. Affected deployments must have multiple authentication realms configured with users sharing the same username across realms. An attacker with these conditions can read, modify, and delete another user's private data. The issue is patched in Kibana 8.19.21, 9.4.6, and 9.5.2; no workarounds exist.
Affected products
- Elastic Kibana 8.19.11–8.19.20, 9.3.0–9.4.5, 9.5.0–9.5.1
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Patched in versions 8.19.21, 9.4.6, and 9.5.2