PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78591 Elastic CVE debrief

The CVE-2026-78591 vulnerability is a Medium-severity Path Traversal issue in the Kibana Fleet feature. It allows a low-privileged user to cause a subsequent action taken by a higher-privileged user to act on an unintended target, resulting in the deletion of resources, including accounts with elevated privileges. The vulnerability affects Kibana versions 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3. Elastic Kibana administrators and users with access to the Fleet feature should be aware of this vulnerability and take necessary actions to prevent unauthorized resource deletion. A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.

Vendor
Elastic
Product
Kibana
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Elastic Kibana administrators and users with access to the Fleet feature should be aware of this vulnerability and take necessary actions to prevent unauthorized resource deletion. This includes reviewing and applying Kibana updates, restricting access to the Fleet feature for low-privileged users, and monitoring for suspicious activity related to resource deletion. Additionally, security teams and platform administrators should review the vulnerability and its potential impact on their environments, and plan for vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Technical summary

The CVE-2026-78591 vulnerability is a Medium-severity Path Traversal issue in the Kibana Fleet feature. It allows a low-privileged user to cause a subsequent action taken by a higher-privileged user to act on an unintended target, resulting in the deletion of resources, including accounts with elevated privileges. The vulnerability affects Kibana versions 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3. This issue requires prompt attention to prevent unauthorized resource deletion. A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.

Defensive priority

Medium-severity vulnerability in Kibana Fleet feature requires prompt attention to prevent unauthorized resource deletion.

Recommended defensive actions

  • Review and apply Kibana updates to affected versions
  • Restrict access to Kibana Fleet feature for low-privileged users
  • Monitor for suspicious activity related to resource deletion
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE-2026-78591 record indicates a Medium-severity vulnerability in the Kibana Fleet feature, allowing for unauthorized deletion of resources via Path Traversal. A low-privileged user could cause a subsequent action taken by a higher-privileged user to act on an unintended target. The vulnerability affects Kibana versions 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78591 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78591

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78591 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78591

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-159/390114

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.