PatchSiren cyber security CVE debrief
CVE-2026-78595 Elastic CVE debrief
An authenticated user with read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and access diagnostic content from agents in other Kibana spaces due to missing authorization in the Kibana Fleet feature. This issue, tracked as CVE-2026-78595, was publicly disclosed on September 3, 2026. The vulnerability allows information disclosure via Privilege Abuse (CAPEC-122). Defenders should assess exposure, especially in deployments with multiple spaces and users with read-level Fleet agent privileges, and prioritize verification and potential mitigations.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-03
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-03
- Advisory updated
- 2026-09-03
Who should care
Defenders responsible for Kibana deployments, especially those with multiple spaces and users with read-level Fleet agent privileges, should assess exposure and prioritize verification and potential mitigations.
Why it matters
CVE-2026-78595 is a medium-severity vulnerability in Kibana's Fleet feature that allows information disclosure due to missing authorization. Defenders should verify exposure, especially in deployments with multiple spaces and users with read-level Fleet agent privileges, and prioritize mitigations to prevent potential information disclosure.
- Potential information disclosure due to unauthorized access to agent metadata and diagnostic content.
- Possible enumeration of agent metadata by users with read-level Fleet agent privileges.
- Need for verification of Kibana deployment configurations and user privileges.
- Potential requirement for compensating controls to mitigate information disclosure risks.
Technical summary
CVE-2026-78595 is a missing authorization vulnerability in the Kibana Fleet feature. An authenticated user with read-level Fleet agent privileges in one Kibana space can enumerate agent metadata and access diagnostic content from agents in other Kibana spaces. This issue allows potential information disclosure due to unauthorized access to agent metadata and diagnostic content. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Elastic's security update ESA-2026-153 discusses the issue and provides mitigation guidance. The CVE record and NVD entry provide details on the vulnerability, including its description and potential impacts. Defenders should verify exposure in Kibana deployments, especially those with multiple spaces and users with read-level Fleet agent privileges. They should assess the need for compensating controls and monitor for potential information disclosure. The vulnerability is tracked as CWE-862, Missing Authorization, and CAPEC-122, Privilege Abuse. The issue was publicly disclosed on September 3, 2026, and has not been modified since then. The CVE record was published on 2026-09-03T19:17:28.850Z. The NVD entry provides additional details on the vulnerability, including its CVSS score and severity. The Elastic security update provides mitigation guidance for the vulnerability. The vulnerability affects Kibana's Fleet feature, which is used for managing and monitoring agents. The issue can be exploited by an authenticated user with read-level Fleet agent privileges in one Kibana space. The vulnerability does not require any special conditions or configurations to be exploited. The issue can be mitigated by applying vendor-provided patches or mitigations. The CVE record and NVD entry provide additional details on the vulnerability and its potential impacts. Defenders should prioritize verifying exposure in Kibana deployments and assess the need for compensating controls. The vulnerability has a medium severity and a CVSS score of 4.3. The issue is tracked as CVE-2026-78595 and CWE-862. The vulnerability affects Kibana's Fleet feature and can be exploited by an authenticated user with read-level Fleet agent privileges. The CVE-
Defensive priority
Defenders should prioritize verifying exposure in Kibana deployments, especially those with multiple spaces and users with read-level Fleet agent privileges. They should assess the need for compensating controls and monitor for potential information disclosure.
Recommended defensive actions
- Verify Kibana deployment configurations and user privileges.
- Assess the need for compensating controls.
- Monitor for potential information disclosure.
- Apply vendor-provided patches or mitigations.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Elastic's security update ESA-2026-153 discusses the issue and provides mitigation guidance. The vulnerability affects Kibana's Fleet feature, which is used for managing and monitoring agents. The issue can be exploited by an authenticated user with read-level Fleet agent privileges in one Kibana space. To verify exposure, defenders should review Kibana deployment configurations and user privileges, assess the need for compensating controls, and monitor for potential information disclosure. The Elastic security update provides mitigation guidance for the vulnerability. The CVE record was published on 2026-09-03T19:17:28.850Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78595 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78595
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78595 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78595
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-9-4-6-9-5-3-security-update-esa-2026-153/390160
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.