VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-78598

CVE-2026-78598: Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiti

Published Sep 2, 2026 CVSS 5.4

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.

Affected AI Products

machine learning
Get the weekly digest. Every Monday: top AI security stories of the week. Free.