Authorization Bypass in Kibana Affects Elastic
CVE-2026-78581
4.2MEDIUM
What is CVE-2026-78581?
An issue in Kibana allows an authenticated user to bypass authorization controls through a user-controlled key. This vulnerability permits access to another user's AI Assistant conversations by leveraging an inadequately secured identifier. Exploitation requires knowledge of a specific identifier, making it a targeted issue. Organizations using affected Kibana versions should take immediate action to secure their data and ensure access controls are respected.
Affected Version(s)
Kibana 8.0.0 <= 8.16.2