Information Disclosure in Kibana by Elastic
CVE-2026-78603
4.3MEDIUM
What is CVE-2026-78603?
A vulnerability in Kibana allows authenticated users with minimal Elasticsearch privileges to bypass authorization mechanisms. This oversight can lead to an unauthorized disclosure of sensitive Fleet deployment metadata from the default Kibana space, thus compromising data integrity and privacy.
Affected Version(s)
Kibana 9.0.0 <= 9.4.5
Kibana 9.5.0