SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78606

MEDIUM · CVSS 4.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kibana is vulnerable to incorrect authorization, allowing authenticated users from different realms with the same username to access, modify, and delete each other's private Elastic AI Assistant Knowledge Base entries. This could lead to unauthorized data disclosure and manipulation, posing a risk to data integrity and confidentiality. Organizations using Kibana should prioritize addressing this vulnerability to protect sensitive information and maintain proper access controls.

CVE
CVE-2026-78606
Severity
MEDIUM
CVSS
4.2
EPSS
0.15%

Original NVD Description

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.

Related CVEs

Other vulnerabilities affecting the same vendor(s)