CVE-2026-78595: Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure

Published Sep 3, 2026
·
Updated

Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and access diagnostic content belonging to agents enrolled in other Kibana spaces.

Affected Software

1 affected component
Elastic Kibana

Event History

Sep 3, 2026
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is able to exploit this issue?

An authenticated Kibana user with read-level Fleet agent privileges in at least one Kibana space could exploit it. No user interaction is required.

2

What information could be exposed?

The user could enumerate agent metadata and access diagnostic content for agents enrolled in other Kibana spaces.

3

Does exploiting this issue require access to the affected agents themselves?

The disclosed data is accessed through Kibana Fleet authorization bypass, using the user's existing Fleet agent read-level privileges in one space. The provided information does not indicate that direct access to the agents is required.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203