CVE-2026-78598
EUVD-2026-7005902.09.2026, 15:17
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | kibana | 8.0.0 ≤ 𝑥 ≤ 8.19.18 | CNA |
| elastic | kibana | 9.0.0 ≤ 𝑥 ≤ 9.3.7 | CNA |
| elastic | kibana | 9.4.0 ≤ 𝑥 ≤ 9.4.3 | CNA |
Vulnerability Media Exposure