PatchSiren cyber security CVE debrief
CVE-2026-78591 Elastic CVE debrief
The CVE-2026-78591 vulnerability is a Medium-severity Path Traversal issue in the Kibana Fleet feature. It allows a low-privileged user to cause a subsequent action taken by a higher-privileged user to act on an unintended target, resulting in the deletion of resources, including accounts with elevated privileges. The vulnerability affects Kibana versions 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3. Elastic Kibana administrators and users with access to the Fleet feature should be aware of this vulnerability and take necessary actions to prevent unauthorized resource deletion. A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Elastic Kibana administrators and users with access to the Fleet feature should be aware of this vulnerability and take necessary actions to prevent unauthorized resource deletion. This includes reviewing and applying Kibana updates, restricting access to the Fleet feature for low-privileged users, and monitoring for suspicious activity related to resource deletion. Additionally, security teams and platform administrators should review the vulnerability and its potential impact on their environments, and plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Technical summary
The CVE-2026-78591 vulnerability is a Medium-severity Path Traversal issue in the Kibana Fleet feature. It allows a low-privileged user to cause a subsequent action taken by a higher-privileged user to act on an unintended target, resulting in the deletion of resources, including accounts with elevated privileges. The vulnerability affects Kibana versions 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3. This issue requires prompt attention to prevent unauthorized resource deletion. A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
Defensive priority
Medium-severity vulnerability in Kibana Fleet feature requires prompt attention to prevent unauthorized resource deletion.
Recommended defensive actions
- Review and apply Kibana updates to affected versions
- Restrict access to Kibana Fleet feature for low-privileged users
- Monitor for suspicious activity related to resource deletion
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE-2026-78591 record indicates a Medium-severity vulnerability in the Kibana Fleet feature, allowing for unauthorized deletion of resources via Path Traversal. A low-privileged user could cause a subsequent action taken by a higher-privileged user to act on an unintended target. The vulnerability affects Kibana versions 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78591 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78591
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78591 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78591
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-159/390114
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.