CVE-2026-78598: Elastic Kibana

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.

Affected products

  • Elastic Kibana: from 8.0.0, before 8.19.19 (fixed in 8.19.19); from 9.0.0, before 9.3.8 (fixed in 9.3.8); from 9.4.0, before 9.4.4 (fixed in 9.4.4)

Published 2026-09-02. Last modified 2026-09-03.