Elastic Kibana Patches Multiple Vulnerabilities
CERT-FR advisory details multiple Kibana vulnerabilities allowing privilege escalation, denial of service, and confidentiality breaches, fixed in versions 8.19.21, 9.4.6 and 9.5.3.
CERT-FR has published an advisory covering multiple vulnerabilities affecting Elastic Kibana, impacting the 8.x branch prior to 8.19.21, the 9.4.x branch prior to 9.4.6, and the 9.5.x branch prior to 9.5.3. The flaws collectively enable an attacker to escalate privileges, cause a remote denial of service, bypass security policy controls, and compromise data confidentiality, though the advisory does not indicate active exploitation in the wild.
Seven CVEs are referenced (CVE-2026-78583, CVE-2026-78593, CVE-2026-78595, CVE-2026-78596, CVE-2026-82298, CVE-2026-82299, CVE-2026-82302), corresponding to seven separate Elastic security bulletins issued on 3 September 2026. No technical exploitation details are provided in the advisory itself; defenders should consult Elastic's linked bulletins for per-CVE severity and affected component details.
Remediation is straightforward: organizations running affected Kibana versions should upgrade to 8.19.21, 9.4.6, or 9.5.3 as applicable. Given Kibana's common deployment as an administrative interface for Elasticsearch stacks, prompt patching is recommended for any internet-facing or multi-tenant instances, particularly where the privilege escalation and confidentiality issues could be chained with existing access.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1113
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free