CVE-2026-78603 is a vulnerability in Elastic Kibana
Published on September 1, 2026
Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Metadata
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.
Vulnerability Analysis
CVE-2026-78603 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-78603 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-78603
Want to know whenever a new CVE is published for Elastic Kibana? stack.watch will email you.
Affected Versions
Elastic Kibana:- Version 9.0.0, <= 9.4.5 is affected.
- Version 9.5.0 is affected.