Impact
The vulnerability is an authorization flaw in Kibana’s machine learning subsystem. An authenticated user with job‑management privileges in one Kibana space can cause the machine‑learning job’s saved object to become visible across all spaces in the instance, even to users lacking access to those spaces. This flaw – identified as CWE‑863 – can lead to confidential machine‑learning data leakage and compromise the isolation guarantees normally provided by spaces.
Affected Systems
The affected product is Elastic’s Kibana platform. No specific version ranges are provided in the advisory, so all releases that include the machine‑learning feature and have not yet been patched by the ESA‑2026‑156 update are potentially vulnerable. Server administrators should verify whether their Kibana instance uses a version prior to the latest security release.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with job‑management rights; the attacker then triggers cross‑space visibility of the ML job. Because the flaw only allows data disclosure and does not provide remote code execution or privilege escalation, the overall risk is limited to confidentiality breach of machine‑learning job data.
OpenCVE Enrichment