CVE-2026-78582

EUVD-2026-87794
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
elasticCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
elastickibana
7.12.0 ≤
𝑥
≤ 7.17.29
CNA
elastickibana
8.0.0 ≤
𝑥
≤ 8.19.21
CNA
elastickibana
9.0.0 ≤
𝑥
≤ 9.4.6
CNA
elastickibana
9.5.0 ≤
𝑥
≤ 9.5.2
CNA