Incorrect Authorization in Kibana's Machine Learning Feature
CVE-2026-78598

5.4MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-78598?

A vulnerability in Kibana's machine learning feature allows an authenticated user with job management privileges to expose saved objects across all Kibana spaces. This misconfiguration of access control can result in sensitive information being disclosed to users without proper access rights, raising concerns about data security and protection within the application.

Affected Version(s)

Kibana 8.0.0 <= 8.19.18

Kibana 9.0.0 <= 9.3.7

Kibana 9.4.0 <= 9.4.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.