CVE-2026-78582 MEDIUM

CVE-2026-78582: Missing Authorization in Kibana Leading to Unauthorized Deletion of Data

Vendor Elastic
Product Kibana
Weakness CWE-862 · Missing authorization
Published September 26, 2026
Last update September 26, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.

Key dates

02Disclosure timeline

September 26, 2026 CVE published

Related vulnerabilities

04Related CVE