{"id":"CVE-2026-78603","summary":"Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Metadata","details":"Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.","modified":"2026-09-04T11:45:39.627763506Z","published":"2026-09-01T19:20:35.832Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78603.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"9.0.0"},{"last_affected":"9.4.5"},{"introduced":"9.5.0"},{"last_affected":"9.5.0"}]}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-9-4-6-9-5-1-security-update-esa-2026-149/390069"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78603.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78603"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"112859b85d50de2a7e63f73c8fc70b99eea24291"},{"fixed":"10011cbc74640115d0ffac0cef7c925aec4754f5"},{"introduced":"8d4246a64bc255212407b1b313fe402391299c88"},{"last_affected":"8d4246a64bc255212407b1b313fe402391299c88"}],"database_specific":{"extracted_events":[{"introduced":"9.0.0"},{"fixed":"9.4.6"},{"introduced":"9.5.0"},{"last_affected":"9.5.0"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*"]}}],"versions":["9.5.0","v9.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78603.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"240f7d17d21408117f4295bcf74d48092ab0d078"},{"last_affected":"240f7d17d21408117f4295bcf74d48092ab0d078"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.5.0"},{"last_affected":"9.5.0"}],"source":"CPE_STRING"}}],"versions":["9.5.0","v9.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78603.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}