CVE-2026-78584: Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
Published Sep 2, 2026
·Updated
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
Affected Software
1 affected component
Elastic Kibana
Event History
Sep 2, 2026
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need?
The attacker must be authenticated and hold Osquery live-query privileges.
2
What information can be exposed across space boundaries?
A privileged Osquery user can determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
3
Is interaction from another user required?
No user interaction is required.