VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-82293

CVE-2026-82293: Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption v

Published Sep 2, 2026 CVSS 4.3

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster resources they should not be able to reach.

Affected AI Products

machine learning
Get the weekly digest. Every Monday: top AI security stories of the week. Free.