Junglewise Threat Intelligence

CVE-2026-82299: Elastic Kibana authorization bypass leading to information disclosure

CVE-2026-82299 · Severity: medium · CVSS 6.5 · Published 2026-09-03

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a data visualization and exploration platform used to analyze logs and metrics, contains an authorization flaw that allows authenticated users to access sensitive information they should not be able to see. The vulnerability requires Fleet debugging interfaces to be enabled and affects all Kibana 9.x versions up to 9.5.2. An attacker with valid credentials can exploit incorrectly configured access controls to view confidential data.

Technical details

This is an Incorrect Authorization (CWE-863) vulnerability in Kibana that allows authenticated users to bypass access control checks via exploitation of misconfigured security levels (CAPEC-180). The vulnerability was introduced in version 9.0.0 and only affects the 9.x release line; version 8.x is unaffected. Exploitation requires: (1) an authenticated user account, (2) network access to Kibana, and (3) Fleet debugging interfaces to be enabled in the configuration. An attacker can achieve information disclosure by accessing resources outside their intended permission scope. The issue is resolved in Kibana versions 9.4.6 and 9.5.3; no workarounds are available for unpatched systems.

Affected products

  • Elastic Kibana 9.0.0 to 9.4.5, 9.5.0 to 9.5.2

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Fixed in Kibana 9.4.6 and 9.5.3

References

Related threats