Authorization Bypass in Kibana Affects Elastic
CVE-2026-78581

4.2MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-78581?

An issue in Kibana allows an authenticated user to bypass authorization controls through a user-controlled key. This vulnerability permits access to another user's AI Assistant conversations by leveraging an inadequately secured identifier. Exploitation requires knowledge of a specific identifier, making it a targeted issue. Organizations using affected Kibana versions should take immediate action to secure their data and ensure access controls are respected.

Affected Version(s)

Kibana 8.0.0 <= 8.16.2

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.