Observable Response Discrepancy in Kibana - CVE-2026-78584
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to observable response discrepancy in the Osquery feature when checking scheduled query identifiers across Kibana spaces. A remote user can determine whether a scheduled query identifier exists in a space they are not authorized to access to disclose sensitive information.
Only deployments with the Osquery feature enabled and multiple Kibana spaces configured are affected.