Authorization Flaw in Kibana's Machine Learning Feature
CVE-2026-63145
4.3MEDIUM
What is CVE-2026-63145?
A vulnerability is present in Kibana's Machine Learning functionality, where an inadequate authorization check permits users with limited privileges to access and manipulate audit and notification records for various Machine Learning jobs. This condition arises from the failure to properly constrain access control lists (ACLs) on a critical endpoint, enabling unauthorized actions that could compromise the integrity of data related to Machine Learning operations across multiple user spaces.
Affected Version(s)
Kibana 9.4.0 <= 9.4.3
Kibana 9.0.0 <= 9.3.7
Kibana 8.0.0 <= 8.19.18