← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 26, 2026 · 20:42via CVEFeed

CVE-2026-78582 - Missing Authorization in Kibana Leading to Unauthorized Deletion of Data

Brief

CVE ID : CVE-2026-78582

Published : Sept. 26, 2026, 8:42 p. m.

  • 18 minutes ago

Description : Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to.

Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.

Severity: 6.5

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→