Description
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.
Published: 2026-09-02
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization flaw in Kibana’s machine learning subsystem. An authenticated user with job‑management privileges in one Kibana space can cause the machine‑learning job’s saved object to become visible across all spaces in the instance, even to users lacking access to those spaces. This flaw – identified as CWE‑863 – can lead to confidential machine‑learning data leakage and compromise the isolation guarantees normally provided by spaces.

Affected Systems

The affected product is Elastic’s Kibana platform. No specific version ranges are provided in the advisory, so all releases that include the machine‑learning feature and have not yet been patched by the ESA‑2026‑156 update are potentially vulnerable. Server administrators should verify whether their Kibana instance uses a version prior to the latest security release.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with job‑management rights; the attacker then triggers cross‑space visibility of the ML job. Because the flaw only allows data disclosure and does not provide remote code execution or privilege escalation, the overall risk is limited to confidentiality breach of machine‑learning job data.

Generated by OpenCVE AI on September 3, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Kibana to the latest security update (ESA‑2026‑156 or newer).
  • Revoke or reduce machine‑learning job management privileges for users who do not require cross‑space access.
  • Verify that access control lists for each space are correctly configured and that no default or unintended inheritance of ML job objects exists.
  • Conduct an audit of machine‑learning job objects to identify any that are already exposed across spaces and adjust permissions accordingly.

Generated by OpenCVE AI on September 3, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Thu, 03 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.
Title Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job Data
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T15:58:12.114Z

Reserved: 2026-08-24T21:13:51.299Z

Link: CVE-2026-78598

cve-icon Vulnrichment

Updated: 2026-09-02T15:50:46.875Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T15:17:40.863

Modified: 2026-09-03T13:42:26.497

Link: CVE-2026-78598

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:05Z

Weaknesses