4.2
CVE-2026-78581
- EPSS 0.13%
- Veröffentlicht 25.08.2026 13:19:31
- Zuletzt bearbeitet 02.09.2026 14:10:03
- Erkennungen
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.029 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 4.2 | 1.6 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://discuss.elastic.co/t/kibana-8-16-3-8-17-2-security-update-esa-2026-51/387446