Kibana 8.x < 8.19.22 / 9.0.x < 9.4.7 / 9.5.x < 9.5.3 Missing Authorization (ESA-2026-139)

medium Nessus Plugin ID 351486

Synopsis

The remote host is affected by a missing authorization vulnerability.

Description

The version of Kibana installed on the remote host is 8.x prior to 8.19.22, or 9.0.x prior to 9.4.7, or 9.5.x prior to 9.5.3. It is, therefore, affected by a vulnerability as referenced in the ESA-2026-139 advisory.

- Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply. (CVE-2026-78582)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

The issue is resolved in Kibana version 8.19.22, 9.4.7, 9.5.3.

See Also

https://discuss.elastic.co/t/390680

Plugin Details

Severity: Medium

ID: 351486

File Name: kibana_esa_2026_139.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.61

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2026-78582

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:elasticsearch:kibana

Required KB Items: installed_sw/Kibana

Exploit Ease: No known exploits are available

Patch Publication Date: 9/25/2026

Vulnerability Publication Date: 9/26/2026

Reference Information

CVE: CVE-2026-78582