Information Disclosure Vulnerability in Kibana by Elastic
CVE-2026-78584
4.3MEDIUM
What is CVE-2026-78584?
An observable response discrepancy in the Osquery feature of Kibana allows authenticated users with live-query privileges to determine the existence of scheduled query identifiers in unauthorized Kibana spaces. This could potentially lead to unauthorized information disclosure, exposing sensitive data within affected instances.
Affected Version(s)
Kibana 9.4.0 <= 9.4.3