Junglewise Threat Intelligence

CVE-2026-78598: Elastic Kibana machine learning privilege escalation via space boundary bypass

CVE-2026-78598 · Severity: medium · CVSS 5.4 · Published 2026-09-02

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and analytics platform used to monitor and analyze data in Elasticsearch clusters. A vulnerability in its machine learning feature allows an authenticated user with job management privileges in one space to expose machine learning job data to all other spaces in the same Kibana instance, even if that user lacks access rights to those other spaces. This can result in unauthorized access to sensitive analytics data and dashboards across the organization.

Technical details

The vulnerability is an incorrect authorization flaw (CWE-863) in Kibana's machine learning feature that fails to properly enforce space-level access controls. An authenticated user holding machine learning job management privileges within a single Kibana space can manipulate a job's saved object to become accessible across all spaces in the Kibana instance without authorization. The attack requires authentication and user interaction to create or modify a machine learning job, but no special privileges are needed beyond existing job management roles within one space. The vulnerability allows information disclosure and potential modification of machine learning job data across unauthorized space boundaries. Patches are available in Kibana 8.19.19, 9.3.8, and 9.4.4.

Affected products

  • Elastic Kibana 8.0.0–8.19.18, 9.0.0–9.3.7, 9.4.0–9.4.3

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in Kibana 8.19.19, 9.3.8, and 9.4.4

References

Related threats