Kibana Missing Auth: Unauthorized Deletion of Synthetics Monitors
CVE-2026-78582 Published on September 26, 2026
Missing Authorization in Kibana Leading to Unauthorized Deletion of Data
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.
Vulnerability Analysis
CVE-2026-78582 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-78582 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-78582
Want to know whenever a new CVE is published for Elastic Kibana? stack.watch will email you.
Affected Versions
Elastic Kibana:- Version 7.12.0, <= 7.17.29 is affected.
- Version 8.0.0, <= 8.19.21 is affected.
- Version 9.0.0, <= 9.4.6 is affected.
- Version 9.5.0, <= 9.5.2 is affected.