Incorrect authorization in Kibana - CVE-2026-82293
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to cause unauthorized resource consumption.
The vulnerability exists due to incorrect authorization in the Kibana machine learning feature when invoking machine learning functionality beyond the intended authorization scope. A remote user can invoke machine learning functionality beyond their authorization scope to cause unauthorized resource consumption.
Only configurations with machine learning features enabled are vulnerable.