Incorrect Authorization in Kibana Machine Learning Feature by Elastic
CVE-2026-82293
4.3MEDIUM
What is CVE-2026-82293?
An issue within Kibana's machine learning feature allows authenticated users to perform actions beyond their permitted scope due to misconfigured access controls. This improper authorization can lead to excessive resource consumption on the cluster, potentially impacting overall system performance and availability. Organizations utilizing Kibana should review their security settings and ensure proper configuration to protect against these risks.
Affected Version(s)
Kibana 8.0.0 <= 8.19.20
Kibana 9.0.0 <= 9.4.5
Kibana 9.5.0 <= 9.5.1