CVE-2026-78598: Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiti
mediumvulnerability
security
Summary
A flaw in Kibana's machine learning feature allows an authenticated user with job management privileges in one space (an isolated area in Kibana) to accidentally make a job's saved object accessible across all spaces in the system, even if they don't have permission to access those other spaces. This could expose sensitive information to users who shouldn't see it.
Vulnerability Details
CVSS Score
5.4(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
network
Attack Complexity
low
Privileges Required
low
User Interaction
none
Disclosure Date
September 2, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
confidentialityintegrity
AI Component TargetedInference
Affected Vendors
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78598
First tracked: September 2, 2026 at 02:07 PM
Classified by LLM (prompt v3) · confidence: 75%