Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-78598

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 5.4


Contact Us

Shodan ® - All rights reserved