Executive brief
Kibana, a web-based analytics and search interface used to explore and visualize data stored in Elasticsearch, contains an authorization flaw in its machine learning features. An authenticated user could bypass access controls and invoke machine learning functionality beyond their assigned permissions, consuming cluster resources they should not be able to access and potentially disrupting service availability for other users.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in Kibana's machine learning feature that allows authenticated users to access functionality beyond their authorization scope. The vulnerability exploits incorrectly configured access control security levels (CAPEC-180), allowing an authenticated attacker to consume cluster resources they should not be able to reach. Attack vector is network-based and requires prior authentication; no user interaction is required. The impact is limited to availability (resource exhaustion), with no confidentiality or integrity impact. Patches are available in Kibana versions 8.19.21, 9.4.6, and 9.5.2; no workarounds exist for versions prior to these releases.
Affected products
- Elastic Kibana 8.0.0 to 8.19.20; 9.0.0 to 9.4.5; 9.5.0 to 9.5.1
Timeline
- 2026-09-01: disclosed: Public disclosure via Elastic security advisory ESA-2026-169
- 2026-09-02: patched: Patches released in Kibana 8.19.21, 9.4.6, and 9.5.2