CVE-2026-82299: Incorrect Authorization in Kibana Leading to Information Disclosure
Published Sep 3, 2026
·Updated
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Affected Software
1 affected component
Elastic Kibana
Event History
Sep 3, 2026
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs network access and low-level privileges in Kibana. No user interaction is required, and the attack complexity is rated low.
2
What is the expected security impact beyond data exposure?
The reported impact is high confidentiality impact. No integrity or availability impact is indicated by the supplied CVSS vector.