CVE-2026-78582
EUVD-2026-8779426.09.2026, 21:16
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | kibana | 7.12.0 ≤ 𝑥 ≤ 7.17.29 | CNA |
| elastic | kibana | 8.0.0 ≤ 𝑥 ≤ 8.19.21 | CNA |
| elastic | kibana | 9.0.0 ≤ 𝑥 ≤ 9.4.6 | CNA |
| elastic | kibana | 9.5.0 ≤ 𝑥 ≤ 9.5.2 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure