SB2026090224 - Incorrect authorization in Kibana
Published: September 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect authorization (CVE-ID: CVE-2026-82293)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause unauthorized resource consumption.
The vulnerability exists due to incorrect authorization in the Kibana machine learning feature when invoking machine learning functionality beyond the intended authorization scope. A remote user can invoke machine learning functionality beyond their authorization scope to cause unauthorized resource consumption.
Only configurations with machine learning features enabled are vulnerable.
Remediation
Install update from vendor's website.