Description
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
Published: 2026-09-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature enables an authenticated user who holds live‑query privileges to determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access. The vulnerability can reveal the presence of scheduled queries across spaces, enabling attackers to enumerate sensitive data or configuration details. The impact is an information disclosure that compromises confidentiality within the affected Kibana environment.

Affected Systems

Elastic Kibana is affected. No specific version information was supplied, so all installations that include the Osquery feature may be subject to this vulnerability until a patch is released.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires authentication with live‑query privileges, so the attack vector is limited to authenticated users. An attacker with such privileges can enumerate scheduled queries across spaces, but no remote code execution or denial of service is possible. The overall risk is moderate, with a realistic likelihood that an attacker could leverage existing credentials to gain additional hidden information.

Generated by OpenCVE AI on September 3, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy any Elastic Kibana update that fixes the observable response discrepancy as soon as it becomes available.
  • Restrict the Osquery live‑query privilege to only those users who genuinely require it, using role‑based access controls.
  • Disable or remove the Osquery feature in Kibana environments where it is not needed to reduce attack surface.

Generated by OpenCVE AI on September 3, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Thu, 03 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
Title Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T15:58:11.488Z

Reserved: 2026-08-24T21:13:45.972Z

Link: CVE-2026-78584

cve-icon Vulnrichment

Updated: 2026-09-02T15:50:17.957Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T15:17:39.943

Modified: 2026-09-03T13:41:38.313

Link: CVE-2026-78584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:05Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy