Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the Metrics Experience feature did not enforce a Kibana-level authorization check that an equivalent, related API in the same feature did enforce. As a result, a user who held only data-store-level read access to an index, but no corresponding Kibana feature privilege, could retrieve index-derived metric data through Kibana that the properly-authorized API would otherwise have blocked.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Elastic Kibana | — | Upgrade Elastic Kibana to the latest version | Oct 7, 2026 | Oct 6, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub