CVE-2026-78583

8.1

Elastic · Kibana

A privilege escalation vulnerability in Kibana allows authenticated users with Fleet management rights to elevate Elastic Agent credentials to full cluster administration privileges.

Executive summary

An incorrect authorization vulnerability in Elastic Kibana allows authenticated users to escalate privileges, potentially leading to full cluster compromise.

Vulnerability

This is an improper authorization flaw (CWE-863) where Kibana fails to validate Elasticsearch cluster privilege declarations from integration packages. An authenticated user with Fleet management privileges can manipulate input data to mint credentials for Elastic Agents that possess excessive administrative rights.

Business impact

Successful exploitation allows an attacker to gain full administrative control over the Elasticsearch cluster, posing a severe risk to data confidentiality and integrity. With a CVSS score of 8.1, the high severity reflects the potential for complete system compromise within the Elastic stack, which could lead to unauthorized data access, modification, or destruction of critical business intelligence.

Remediation

Immediate Action: Upgrade to the patched versions as specified in the official Elastic security advisory (ESA-2026-140) to ensure proper validation of privilege declarations.

Proactive Monitoring: Review audit logs for unusual credential minting activities or modifications to Elastic Agent policies by users with Fleet management access.

Compensating Controls: Restrict Fleet management privileges to the minimum number of trusted administrators until the software can be patched to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention to prevent unauthorized administrative escalation. Organizations running affected versions of Kibana must prioritize updating to the latest secure release to remediate the authorization logic flaw and secure their Elasticsearch clusters against potential abuse.

More Elastic CVEs

Sources