CVE-2026-78581: Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Kibana user could exploit it if they know another user's hard-to-guess AI Assistant conversation identifier. The issue affects access to AI Assistant conversations rather than requiring unauthenticated access.
What could an attacker do with a conversation identifier?
They could access or modify an AI Assistant conversation that they do not own. The provided information describes confidentiality and integrity impact, with no availability impact.
Is exploitation likely without prior knowledge of a target conversation?
Successful exploitation requires knowledge of the target conversation's hard-to-guess identifier. The attack complexity is rated high, so obtaining or otherwise knowing that identifier is a necessary condition.