Kibana 9.4.0 Security Update (ESA-2026-191)

Missing Authorization in Kibana Leading to Information Disclosure

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the Metrics Experience feature did not enforce a Kibana-level authorization check that an equivalent, related API in the same feature did enforce. As a result, a user who held only data-store-level read access to an index, but no corresponding Kibana feature privilege, could retrieve index-derived metric data through Kibana that the properly-authorized API would otherwise have blocked.

Affected Versions:

  • 9.x: All versions from 9.2.0 up to and including 9.3.8

Users on the 8.x release line are not affected. The Metrics Experience functionality that contains this vulnerability was introduced in version 9.2.0 and is not present in earlier releases. Users on the 9.4.x and later release lines are not affected because the affected functionality was removed entirely from Kibana in version 9.4.0.

Affected Configurations:

  • All configurations running an affected version with the Metrics Experience feature present are affected. Exposure requires that a user already hold read access to a data index at the underlying data-store layer, independent of their Kibana feature privileges.

Solutions and Mitigations:

This vulnerability is resolved by upgrading to version 9.4.0 or later, in which the affected Metrics Experience functionality was removed entirely. There is no patched release within the 9.2.x or 9.3.x lines; those lines are no longer receiving new releases, so affected customers must upgrade to a currently maintained release line. Elastic recommends upgrading to the most recent release available, and reviewing the known issues for your target version before upgrading.

For Users that Cannot Upgrade:

There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 4.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVE ID: CVE-2026-102410
Problem Type: CWE-862 - Missing Authorization