SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-78598

MEDIUM · CVSS 5.4 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-05

CyberRota Analysis

AI-Generated

The vulnerability allows an authenticated user with machine learning job management privileges in a single Kibana space to improperly access saved objects across all spaces within the Kibana instance, potentially leading to unauthorized information disclosure. Organizations using Kibana, particularly those leveraging its machine learning features, should prioritize addressing this issue to prevent unauthorized access to sensitive data. Properly configuring access control security levels is essential to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78598
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.

Related CVEs

Other vulnerabilities affecting the same vendor(s)