Authorization Flaw in Kibana Leads to Data Deletion Risks from Elastic
CVE-2026-78582

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-78582?

A flaw in Kibana allows authenticated users with Synthetics privileges to delete Synthetics monitors across multiple spaces without proper authorization. This vulnerability arises from incorrectly configured access control, enabling users to perform deletion actions on monitors associated with private locations, resulting in the irretrievable loss of data. The flaw bypasses critical authorization checks, posing significant risks to data integrity, particularly for shared monitors that connect to private Elastic Agent configurations.

Affected Version(s)

Kibana 7.12.0 <= 7.17.29

Kibana 8.0.0 <= 8.19.21

Kibana 9.0.0 <= 9.4.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.