# Kibana 5.0.2 released with a fix for improper authentication

**URL:** <https://discuss.elastic.co/t/kibana-5-0-2-released-with-a-fix-for-improper-authentication/67527>\
**Category:** Security Announcements\
**Created:** [November 29, 2016, 5:14pm UTC](https://discuss.elastic.co/t/kibana-5-0-2-released-with-a-fix-for-improper-authentication/67527 "2016-11-29T17:14:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Court](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/court/32/6640_2.png) [@Court](https://discuss.elastic.co/u/Court)\
**Post date:** [November 29, 2016, 5:14pm UTC](https://discuss.elastic.co/t/kibana-5-0-2-released-with-a-fix-for-improper-authentication/67527/1 "2016-11-29T17:14:19Z")

</div>

With X-Pack installed, operations in the Advanced Settings panel of the Management tab and operations from the short URL service were performed as the "Kibana Server" user regardless of the user that is currently authenticated. As a result, a user that was defined as read-only could make changes to the global settings of Kibana. This could allow a rogue user to change Kibana configuration to alter Kibana’s appearance or Kibana’s default index.

5.0.2 ensures these operations are run as the currently authenticated user.

This is described as ESA-2016-10 on our security page.

As always, grab the latest release from our [downloads](https://www.elastic.co/downloads/kibana) page.

For more information about this release, check out the [blog post](https://www.elastic.co/blog/kibana-5-0-2-released) or [release notes](https://www.elastic.co/guide/en/kibana/current/release-notes-5.0.2.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/kibana-5-0-2-released-with-a-fix-for-improper-authentication/67527/2 "2017-07-06T13:46:15Z")

</div>


