{"id":"CVE-2026-78606","summary":"Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data","details":"Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.","modified":"2026-09-04T11:45:39.616416935Z","published":"2026-09-01T19:20:37.599Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78606.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.19.11"},{"last_affected":"8.19.20"},{"introduced":"9.3.0"},{"last_affected":"9.4.5"},{"introduced":"9.5.0"},{"last_affected":"9.5.1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-142/390093"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78606.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78606"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"c5253e1bcb0268a5dafed9dee18e16fd3144d7d6"},{"fixed":"4fe44c255c3d0da06779b921e132cdc555ed9aff"},{"introduced":"17b451d8979a29e31935fe1eb901310350b30e62"},{"fixed":"10011cbc74640115d0ffac0cef7c925aec4754f5"},{"introduced":"8d4246a64bc255212407b1b313fe402391299c88"},{"fixed":"b42549c72e6e040825b13e5d8ebf7ff63886b24d"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.19.11"},{"fixed":"8.19.21"},{"introduced":"9.3.0"},{"fixed":"9.4.6"},{"introduced":"9.5.0"},{"fixed":"9.5.2"}],"source":"CPE_RANGE"}}],"versions":["v8.19.20","v9.5.1","v9.5.0","v8.19.19","v8.19.18","v8.19.17","v8.19.16","v8.19.15","v8.19.14","v8.19.13","v8.19.12","v8.19.11"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78606.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"240f7d17d21408117f4295bcf74d48092ab0d078"},{"fixed":"37dc1e9d6dbf80bb1cf22da5ed258d3f642d2f9c"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.5.0"},{"fixed":"9.5.2"}]}}],"versions":["v9.5.1","v9.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78606.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}