SB2026090224 - Incorrect authorization in Kibana



SB2026090224 - Incorrect authorization in Kibana

Published: September 2, 2026

Security Bulletin ID SB2026090224
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect authorization (CVE-ID: CVE-2026-82293)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause unauthorized resource consumption.

The vulnerability exists due to incorrect authorization in the Kibana machine learning feature when invoking machine learning functionality beyond the intended authorization scope. A remote user can invoke machine learning functionality beyond their authorization scope to cause unauthorized resource consumption.

Only configurations with machine learning features enabled are vulnerable.


Remediation

Install update from vendor's website.