Incorrect authorization in Kibana - CVE-2026-82293

 

Incorrect authorization in Kibana - CVE-2026-82293

Published: September 2, 2026


Vulnerability identifier: #VU146664
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-82293
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause unauthorized resource consumption.

The vulnerability exists due to incorrect authorization in the Kibana machine learning feature when invoking machine learning functionality beyond the intended authorization scope. A remote user can invoke machine learning functionality beyond their authorization scope to cause unauthorized resource consumption.

Only configurations with machine learning features enabled are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-82293

Install security update from vendor's website.

Kibana - addressed in versions 8.19.21, 9.4.6, 9.5.2

External References

Related Security Bulletins