Information Disclosure Vulnerability in Kibana by Elastic
CVE-2026-78601

5.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-78601?

The Kibana product by Elastic experiences a vulnerability stemming from a lack of proper authorization controls. This flaw allows authenticated users with elevated privileges to exploit background tasks, inadvertently accessing sensitive data from Elasticsearch indices that they should not be permitted to view. This exposure can lead to unauthorized information disclosure, significantly undermining data security and privacy.

Affected Version(s)

Kibana 9.4.0 <= 9.4.4

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.