Authorization Flaw in Kibana Affects Elastic
CVE-2026-78597
4.3MEDIUM
What is CVE-2026-78597?
A vulnerability exists in the Kibana Entity Store feature that allows authenticated users with limited Security feature access to perform unauthorized actions. This includes the ability to create and persist Elasticsearch API keys while circumventing the required administrative permissions. Such a weakness in access controls enables potential misuse of functions not properly constrained by access control lists (ACLs), thereby compromising the integrity of security measures.
Affected Version(s)
Kibana 8.0.0 <= 8.19.20
Kibana 9.0.3 <= 9.4.5