CVE-2026-78581
EUVD-2026-6548925.08.2026, 13:19
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 8.0.0 ≤ 𝑥 < 8.16.3 |
| elastic | kibana | 8.17.0 ≤ 𝑥 < 8.17.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration