Vulnerabilities & PatchesEmerging1 src
CVE-2026-78582 - Missing Authorization in Kibana Leading to Unauthorized Deletion of Data
CVE ID : CVE-2026-78582
Published : Sept. 26, 2026, 8:42 p. m.
• 18 minutes ago
Description : Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to.
Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.
Severity: 6.5
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...