Unauthorized Data Manipulation in Kibana by Elastic
CVE-2026-78606
4.2MEDIUM
What is CVE-2026-78606?
A vulnerability in Kibana allows unauthorized users to access, modify, and delete another user's private Elastic AI Assistant Knowledge Base entries. When two authenticated users from different realms share identical usernames, the access control mechanisms fail, resulting in potential data breaches. This could compromise sensitive information and disrupt user operations, emphasizing the need for stringent access control measures.
Affected Version(s)
Kibana 8.19.11 <= 8.19.20
Kibana 9.3.0 <= 9.4.5
Kibana 9.5.0 <= 9.5.1