Junglewise Threat Intelligence

CVE-2026-82298: Elastic Kibana authorization bypass in access control

CVE-2026-82298 · Severity: medium · CVSS 4.3 · Published 2026-09-03

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a visualization and analytics platform for the Elastic Stack used to explore and analyze log and time-series data, contains an access control vulnerability that can be exploited by authenticated users to cause service disruptions. An attacker with valid credentials can bypass authorization checks on configured access control levels, leading to denial of service attacks that impact data availability and operational monitoring.

Technical details

The vulnerability is an Incorrect Authorization (CWE-863) issue in Kibana that occurs when access control is improperly configured, specifically related to Fleet and agent communication message signing. An authenticated attacker (PR:L) can exploit this via the network to bypass access control security levels and trigger a denial of service condition. The vulnerability affects configurations with Fleet and agent communication message signing enabled across Kibana versions 8.0.0–8.19.20, 9.0.0–9.4.5, and 9.5.0–9.5.2. Patches are available in versions 8.19.21, 9.4.6, and 9.5.3. No workarounds exist for unpatched deployments.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.20, 9.0.0 to 9.4.5, 9.5.0 to 9.5.2

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Patches released in versions 8.19.21, 9.4.6, and 9.5.3

References

Related threats