news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans Elastic Kibana (04 septembre 2026)

HighCVSS 8.1
Summary

Multiple vulnerabilities have been discovered in Elastic Kibana, potentially allowing attackers to elevate privileges, cause denial-of-service attacks, and compromise data confidentiality. These vulnerabilities affect specific versions of Kibana, and users are advised to apply the security updates provided by Elastic.

Elastic has identified several security vulnerabilities within Kibana. These vulnerabilities could lead to a range of adverse outcomes, including unauthorized privilege escalation, disruption of service through denial-of-service attacks, and unauthorized access to sensitive data. The affected versions of Kibana include 8.x (prior to 8.19.21), 9.4.x (prior to 9.4.6), and 9.5.x (prior to 9.5.3).

Several CVEs have been assigned to these vulnerabilities: CVE-2026-78583, CVE-2026-78593, CVE-2026-78595, CVE-2026-78596, CVE-2026-82298, and CVE-2026-82299. Elastic recommends applying the security updates detailed in their bulletins. These bulletins are available at: https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-140, https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-151, https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-153, https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-154, https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-174, https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-175, https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-178.

Read the full article at CERT-FR