Kibana 8.19.21, 9.4.6, 9.5.3 Security Update (ESA-2026-154)

Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations

Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope.

Affected Versions:

  • 8.x: All versions from 8.18.3 up to and including 8.19.20
  • 9.x:
    • All versions from 9.0.3 up to and including 9.4.5
    • All versions from 9.5.0 up to and including 9.5.2

Affected Configurations:
All Kibana deployments where the Entity Analytics feature has been initialized in at least one space are affected. Multi-space deployments face a broader impact due to the cross-space nature of the unauthorized operation; however, the underlying authorization deficiency is present regardless of space count.

Solutions and Mitigations:
The issue is resolved in Kibana versions 8.19.21, 9.4.6, and 9.5.3.

For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 4.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVE ID: CVE-2026-78596
Problem Type: CWE-862 - Missing Authorization
Impact: CAPEC-122 - Privilege Abuse