CVE-2026-78593: Improper Control of Generation of Code in Kibana Leading to Privilege Escalation
An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized Elasticsearch permissions.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to Kibana and hold Kibana Fleet management privileges. The issue is relevant where the Cribl integration can be configured by such users.
What access does exploitation provide?
Successful exploitation can cause an Elasticsearch ingest pipeline to be written despite the caller lacking the Elasticsearch permissions normally required to perform that action. The reported impact is integrity-only; no confidentiality or availability impact is specified.
Is unauthenticated or user-assisted exploitation possible?
No. The supplied vector indicates network access, low attack complexity, required low privileges, and no user interaction.