CVE-2026-78583: Incorrect Authorization in Kibana Leading to Privilege Escalation
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs Fleet management privileges in Kibana. No user interaction is required.
Which systems can receive the elevated credentials?
Every Elastic Agent assigned to a policy targeted by the attacker can receive a credential with elevated Elasticsearch cluster privileges, potentially including full cluster administration.