CVE-2026-82302: Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification
Published Sep 3, 2026
·Updated
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Affected Software
1 affected component
kibana
Event History
Sep 3, 2026
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low privileges, and does not require user interaction. An unauthenticated attacker is not indicated by the available data.
2
What is the expected security impact?
The issue can allow unauthorized modification of Kibana configuration. The supplied CVSS metrics indicate high confidentiality and integrity impact, with no availability impact indicated.