CVE-2026-78603

Source
https://cve.org/CVERecord?id=CVE-2026-78603
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78603.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78603
Downstream
Published
2026-09-01T19:20:35.832Z
Modified
2026-09-04T11:45:39.627763506Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Metadata
Details

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78603.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "9.0.0"
                },
                {
                    "last_affected": "9.4.5"
                },
                {
                    "introduced": "9.5.0"
                },
                {
                    "last_affected": "9.5.0"
                }
            ]
        }
    ],
    "cna_assigner": "elastic",
    "cwe_ids": [
        "CWE-862"
    ]
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
Show details
{
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.4.6"
        },
        {
            "introduced": "9.5.0"
        },
        {
            "last_affected": "9.5.0"
        }
    ]
}

Affected versions

9.*
9.5.0
v9.*
v9.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78603.json"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
Show details
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "9.5.0"
        },
        {
            "last_affected": "9.5.0"
        }
    ]
}

Affected versions

9.*
9.5.0
v9.*
v9.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78603.json"