PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78590 Elastic CVE debrief

The CVE-2026-78590 vulnerability, classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory or 'Path Traversal'), affects the Kibana Fleet feature. This vulnerability allows a low-privileged user with Fleet Settings write access to potentially delete privileged resources, such as user accounts, by causing a subsequent administrative action to act on unintended internal resources. The vulnerability has a CVSS score of 7.3 and is considered HIGH severity. Exploitation requires an administrator to interact with the affected Fleet interface. Elastic has provided a security update to address this issue. Organizations should prioritize patching to prevent potential unauthorized deletion of privileged resources. Evidence is based on official CVE Program and NVD records, as well as a vendor advisory.

Vendor
Elastic
Product
Kibana
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Elastic Kibana users, administrators, and security teams should be aware of this vulnerability and take immediate action to protect their environments. Affected operators must review and apply patches or updates provided by Elastic. Platform administrators should restrict access to Fleet Settings to only trusted users with legitimate administrative privileges. Vulnerability management teams should monitor Fleet interface interactions for suspicious activity that could indicate attempted exploitation. Security teams should implement additional logging and monitoring to detect potential unauthorized actions and review compensating controls for exposed systems while remediation is scheduled and verified. Asset owners should track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability may impact organizations using Kibana, especially those with low-privileged users having Fleet Settings write access, and those with inadequate monitoring and logging in place. Review of the supplied official advisory or CVE record is necessary to validate affected scope, severity, and vendor guidance. Planning for vendor-supported updates or mitigations through normal change control is crucial where exposure is confirmed. Implementing additional security measures, such as enhanced monitoring and detection, can help mitigate potential risks associated with this vulnerability. It is essential to confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Checking relevant monitoring, detection, and logs for exposed assets that need extra review is also vital. Therefore, Elastic Kibana users, administrators, and security teams must take immediate action to protect their environments and ensure the security of their systems and data. The CVE record was published on 2026-09-02T15:17:40.433Z and has not been modified since then. The information provided is based on official CVE Program and NVD records, as well as a vendor advisory, ensuring a high level of source confidence. However, it is always recommended to verify the information with the official sources and to stay updated withany

Technical summary

The CVE-2026-78590 vulnerability is classified as CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'). It affects the Kibana Fleet feature and allows a low-privileged user with Fleet Settings write access to potentially delete privileged resources such as user accounts by causing a subsequent administrative action to act on unintended internal resources. The vulnerability has a CVSS score of 7.3 and is considered HIGH severity. Exploitation requires an administrator to interact with the affected Fleet interface.

Defensive priority

Organizations using Kibana should prioritize patching to prevent potential unauthorized deletion of privileged resources.

Recommended defensive actions

  • Apply patches or updates provided by Elastic to address the vulnerability in Kibana's Fleet feature.
  • Restrict access to Fleet Settings to only trusted users with legitimate administrative privileges.
  • Monitor Fleet interface interactions for suspicious activity that could indicate attempted exploitation.
  • Implement additional logging and monitoring to detect potential unauthorized actions.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE-2026-78590 record indicates a Path Traversal vulnerability in Kibana's Fleet feature, allowing low-privileged users with Fleet Settings write access to cause administrative actions on unintended internal resources, potentially leading to the deletion of privileged resources such as user accounts. The vendor, Elastic, has provided a security update. Evidence is based on official CVE Program and NVD records, as well as a vendor advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78590 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78590

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78590 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78590

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/kibana-8-19-18-9-3-6-9-4-3-security-update-esa-2026-158/390113

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.