Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from Elasticsearch indices that user is not authorized to access. Derived entity data from those indices is then exposed through the entity store output. | |
| Title | Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-02T15:58:12.877Z
Reserved: 2026-08-24T21:13:52.889Z
Link: CVE-2026-78601
Updated: 2026-09-02T15:51:23.391Z
Status : Received
Published: 2026-09-02T15:17:41.277
Modified: 2026-09-02T16:17:25.210
Link: CVE-2026-78601
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization