Elastic Kibana: Batch of 15 Vulnerabilities Disclosed, Affecting Authorization and Resource Management
Key findings • Fifteen vulnerabilities disclosed together for Elastic Kibana on September 1, 2026. • Flaws include missing/incorrect authorization, path traversal, and resource allocation iss…

Key findings
- Fifteen vulnerabilities disclosed together for Elastic Kibana on September 1, 2026.
- Flaws include missing/incorrect authorization, path traversal, and resource allocation issues.
- Potential impacts range from information disclosure and data modification to DoS and privilege escalation.
- Two High severity vulnerabilities (CVE-2026-78592, CVE-2026-63137) pose significant risks.
- Users are urged to apply patches promptly based on Elastic's advisories.
On September 1, 2026, a batch of fifteen vulnerabilities was disclosed for Elastic's Kibana, a popular data visualization and exploration tool. The vulnerabilities, all disclosed on the same day, span various security weaknesses including missing or incorrect authorization, path traversal, resource allocation issues, and uncaught exceptions. These flaws could lead to information disclosure, data modification, denial of service, and privilege escalation, impacting users who authenticate to Kibana.
Several vulnerabilities stem from authorization flaws. CVE-2026-78608, a Medium severity vulnerability, involves missing authorization in an APM integration function, potentially exposing APM server credentials to any authenticated user. CVE-2026-78606 and CVE-2026-72641, both rated Medium, highlight incorrect authorization issues where users with shared usernames across different authentication realms could gain unauthorized access to data. Additionally, CVE-2026-78603 and CVE-2026-78597, also Medium severity, detail missing authorization in Kibana's Entity Store feature, allowing low-privileged users to bypass controls and perform administrative actions like unauthorized credential creation. CVE-2026-72633, another Medium severity flaw, allows authenticated users with read-level access to stop security monitoring functions.
Denial of Service (DoS) is a significant concern with several CVEs. CVE-2026-72682, CVE-2026-72652, CVE-2026-72633, and CVE-2026-33465, all rated Medium, involve Allocation of Resources Without Limits or Throttling (CWE-770). These vulnerabilities can be triggered by specially crafted requests from authenticated users, leading to excessive memory consumption and rendering Kibana unavailable. CVE-2026-72644, a Medium severity vulnerability, describes an uncaught exception that can be triggered by manipulating input data, also resulting in a denial of service. CVE-2026-63138, a Medium severity NoSQL injection vulnerability, allows authenticated users to craft input that alters query logic, potentially disclosing sensitive data.
Exploitation and impact are amplified by the potential for privilege escalation and resource abuse. CVE-2026-63137, a High severity vulnerability, allows a user with workflow edit permissions to escalate privileges by causing scheduled workflow executions to run with higher privileges. CVE-2026-78592, another High severity vulnerability, involves Path Traversal (CWE-22) which could lead to the unauthorized deletion of privileged resources. CVE-2026-72654, a Medium severity flaw, involves Execution with Unnecessary Privileges, potentially leading to information disclosure.
The batch of vulnerabilities disclosed on September 1, 2026, affects various versions of Kibana. Users are advised to consult Elastic's official advisories for specific version information and patching details. Promptly applying available updates is crucial to mitigate the risks associated with these authorization, resource management, and path traversal vulnerabilities. Staying informed about Elastic's security releases and applying patches in a timely manner is essential for maintaining the security posture of Kibana deployments.
The clustered disclosure of these fifteen vulnerabilities highlights the importance of regular security audits and prompt patching for Elastic Kibana users. The range of impacts, from data exposure to denial of service and privilege escalation, underscores the need for a comprehensive approach to security management.
The following CVEs were part of this disclosure: CVE-2026-78608, CVE-2026-78606, CVE-2026-78603, CVE-2026-78597, CVE-2026-78592, CVE-2026-72682, CVE-2026-72654, CVE-2026-72652, CVE-2026-72644, CVE-2026-72641, CVE-2026-72633, CVE-2026-72628, CVE-2026-63138, CVE-2026-63137, CVE-2026-33465.