{"id":"CVE-2026-78581","summary":"Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana","details":"Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier.","aliases":["BIT-elk-2026-78581","BIT-kibana-2026-78581"],"modified":"2026-09-04T08:06:28.735867Z","published":"2026-08-25T13:08:11.520Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78581.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.0.0"},{"last_affected":"8.16.2"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"elastic","cwe_ids":["CWE-639"]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-8-16-3-8-17-2-security-update-esa-2026-51/387446"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78581.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78581"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"2eb78bceb86e182dc8f45ab76a704b1bfd352c9d"},{"introduced":"2b6a7fed44faa321997703718f07ee0420804b41"},{"fixed":"747663ddda3421467150de0e4301e8d4bc636b0c"}],"database_specific":{"extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.16.3"},{"introduced":"8.17.0"},{"fixed":"8.17.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*"}}],"versions":["v8.17.1","v8.17.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78581.json","vanir_signatures_modified":"2026-09-04T08:06:28Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/747663ddda3421467150de0e4301e8d4bc636b0c","target":{"file":"server/src/main/java/org/elasticsearch/index/mapper/ObjectMapper.java","function":"setIgnoredValues"},"deprecated":false,"digest":{"function_hash":"263356833667147417207880542417020229118","length":346},"id":"CVE-2026-78581-19a84879"},{"id":"CVE-2026-78581-b11c30a6","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/747663ddda3421467150de0e4301e8d4bc636b0c","target":{"file":"server/src/test/java/org/elasticsearch/index/mapper/IgnoredSourceFieldMapperTests.java"},"deprecated":false,"digest":{"line_hashes":["168799588092401371349937989380744438042","242259272325545759304556204886294254385","78134022479182254435201794946905021050"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/747663ddda3421467150de0e4301e8d4bc636b0c","target":{"file":"server/src/main/java/org/elasticsearch/index/mapper/ObjectMapper.java"},"deprecated":false,"digest":{"line_hashes":["241650658189941592068922497856645279704","245410000860545525443509860004509825878","289885912327545093624921847601875478957","56515432158717916672434292238886754568"],"threshold":0.9},"id":"CVE-2026-78581-c2961f10","signature_type":"Line"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"57ca5e139a33dd2eed927ce98d8231a1f217cd15"},{"fixed":"dcb19b0aa33b03224c55afabee0c5fdd03a6c572"},{"introduced":"86cbc85e621f4f3f701ed230f4e859ac5a80145b"},{"fixed":"d7985c80643203de533d99844eb1b53cae85f8f9"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.16.3"},{"introduced":"8.17.0"},{"fixed":"8.17.2"}],"source":"CPE_RANGE"}}],"versions":["v8.17.1","v8.17.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78581.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}