8.1
CVE-2026-82302
- EPSS 0.2%
- Veröffentlicht 03.09.2026 18:35:44
- Zuletzt bearbeitet 08.09.2026 14:17:41
- Erkennungen
Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerElastic
≫
Produkt
Kibana
Default Statusunaffected
Version <=
8.19.20
Version
8.0.0
Status
affected
Version <=
9.4.5
Version
9.0.0
Status
affected
Version <=
9.5.2
Version
9.5.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.099 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-178/390164