Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and persists Elasticsearch API keys under the caller's identity, bypassing the elevated cluster and Kibana privileges that the documented Entity Store setup flow requires.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic kibana |
|
| Vendors & Products |
Elastic
Elastic kibana |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and persists Elasticsearch API keys under the caller's identity, bypassing the elevated cluster and Kibana privileges that the documented Entity Store setup flow requires. | |
| Title | Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-01T19:39:43.610Z
Reserved: 2026-08-24T21:13:51.299Z
Link: CVE-2026-78597
Updated: 2026-09-01T19:39:40.500Z
Status : Analyzed
Published: 2026-09-01T20:17:23.510
Modified: 2026-09-02T18:50:48.993
Link: CVE-2026-78597
No data.
OpenCVE Enrichment
Updated: 2026-09-02T03:45:04Z