Junglewise Threat Intelligence

CVE-2026-82302: Elastic Kibana authorization bypass in access control

CVE-2026-82302 · Severity: high · CVSS 8.1 · Published 2026-09-03

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, Elastic's log analysis and visualization platform, contains an authorization flaw that allows authenticated users to modify system configurations they should not have access to. This affects deployments with Fleet and agent policy management enabled. An attacker with valid credentials could alter critical cluster settings or policies, potentially compromising data integrity and operational security across the entire Elastic deployment.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Kibana's access control implementation, specifically in how it validates permissions for configuration modifications. The flaw results from incorrectly configured access control security levels (CAPEC-180), allowing users with limited privileges to bypass authorization checks and modify protected settings. The attack requires valid authentication credentials but no elevated privileges; once authenticated, an attacker can make unauthorized configuration changes via the Kibana API or UI. The vulnerability affects all configurations with Fleet and agent policy management enabled. Patches are available in Kibana 8.19.21, 9.4.6, and 9.5.3; no workarounds exist for unpatched systems.

Affected products

  • Elastic Kibana 8.0.0 through 8.19.20; 9.0.0 through 9.4.5; 9.5.0 through 9.5.2

Timeline

  • 2026-09-03: disclosed: Published via ESA-2026-178 and CVE-2026-82302
  • 2026-09-03: patched: Fixes available in Kibana 8.19.21, 9.4.6, and 9.5.3

References

Related threats