VYPR
Vypr IntelligenceAI-generatedSep 3, 2026· 26 CVEs

Elastic Kibana: 25 Authorization and Resource Management Vulnerabilities Disclosed Together

Elastic Kibana faces a major security event with 25 vulnerabilities disclosed, including High severity flaws in authorization and resource management.

Key findings

  • 25 vulnerabilities disclosed for Elastic Kibana between Sept 1-3, 2026, primarily authorization and resource management flaws.
  • High severity flaws include unauthorized configuration modification (CVE-2026-82302) and privilege escalation (CVE-2026-78583).
  • Multiple path traversal vulnerabilities (CVE-2026-78590, CVE-2026-78592) allow unauthorized deletion of privileged resources.
  • Denial of service risks arise from unbounded memory consumption (CVE-2026-78586, CVE-2026-72682) and uncaught exceptions (CVE-2026-72644).
  • Affected features include Kibana Fleet, Machine Learning, APM integration, and Cribl integration.
  • Prompt patching and security review are essential to mitigate risks from this extensive vulnerability batch.

On September 3, 2026, a significant batch of 25 vulnerabilities was disclosed for Elastic's Kibana, a widely-used data visualization and exploration tool. The vulnerabilities, disclosed over a two-day period from September 1st to September 3rd, primarily revolve around authorization flaws and resource management issues, with potential impacts ranging from unauthorized data modification and information disclosure to denial of service and privilege escalation. This coordinated disclosure event highlights ongoing security challenges within the platform.

A dominant theme across many of these CVEs is incorrect or missing authorization (CWE-863, CWE-862). CVE-2026-82302, a High severity vulnerability, allows for unauthorized configuration modification by exploiting incorrectly configured access control security levels. Similarly, CVE-2026-78583, also High severity, can lead to privilege escalation due to unvalidated Elasticsearch cluster privilege declarations for Elastic Agents. Other authorization-related vulnerabilities include CVE-2026-82299 (information disclosure), CVE-2026-82298 (denial of service), CVE-2026-78595 (information disclosure in Fleet), CVE-2026-78601 (information disclosure in Entity Store), CVE-2026-78608 (information disclosure in APM integration), and CVE-2026-78603 (bypassing feature and space access controls).

Path traversal vulnerabilities (CWE-22) represent another critical category within this batch. CVE-2026-78590, a High severity flaw, allows for the unauthorized deletion of privileged resources via path traversal in the Kibana Fleet feature. Other path traversal issues include CVE-2026-78599 and CVE-2026-78591, which also impact the Fleet feature and can lead to unauthorized deletion of resources. CVE-2026-78592, another High severity vulnerability, permits the unauthorized deletion of privileged resources through path traversal in tag management.

Denial of service (DoS) vulnerabilities stemming from resource allocation issues (CWE-770) are also present. CVE-2026-78586 and CVE-2026-72682, both Medium severity, allow authenticated users to consume unbounded amounts of memory, potentially rendering Kibana unavailable. CVE-2026-72652 presents a similar DoS risk through excessive resource consumption. Additionally, CVE-2026-72644, a Medium severity vulnerability, can lead to DoS via an uncaught exception triggered by a specially crafted request to the Observability AI Assistant.

Other notable vulnerabilities include CVE-2026-78593, which involves insufficient validation of a configuration field in Kibana's Cribl integration, allowing for the injection of attacker-controlled expressions into server-side scripts. CVE-2026-78584 (Observable Response Discrepancy) and CVE-2026-78598 (Incorrect Authorization in machine learning) relate to information disclosure. CVE-2026-72654 involves execution with unnecessary privileges in the machine learning feature, leading to information disclosure. CVE-2026-78597 allows unauthorized credential creation, and CVE-2026-78606 involves unauthorized data disclosure, modification, and deletion due to ACL misconfigurations.

Users are strongly advised to consult Elastic's official security advisories for detailed information on affected versions and the specific patches released to address this extensive batch of vulnerabilities. Prompt patching and review of access controls are crucial to mitigate the risks associated with these security flaws. The sheer number and variety of vulnerabilities underscore the importance of continuous security vigilance for Kibana deployments.

The related news coverage from Vypr Intelligence highlights that fifteen of these vulnerabilities were disclosed on September 1, 2026, emphasizing the authorization and resource management aspects. The report also correctly identifies two High severity vulnerabilities (CVE-2026-78592 and another, CVE-2026-63137, which is not in the provided input batch) and urges prompt patching. This coordinated disclosure event serves as a reminder for administrators to stay informed about security updates for critical infrastructure components like Kibana.

AI-written article. Grounded in 26 CVE records listed below.