Information Disclosure Vulnerability in Kibana by Elastic
CVE-2026-78601
5.5MEDIUM
What is CVE-2026-78601?
The Kibana product by Elastic experiences a vulnerability stemming from a lack of proper authorization controls. This flaw allows authenticated users with elevated privileges to exploit background tasks, inadvertently accessing sensitive data from Elasticsearch indices that they should not be permitted to view. This exposure can lead to unauthorized information disclosure, significantly undermining data security and privacy.
Affected Version(s)
Kibana 9.4.0 <= 9.4.4