CVE-2026-82293: Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster resources they should not be able to reach.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be authenticated to Kibana with low privileges. No user interaction is required, and the issue can be exploited over the network.
What is the practical impact of successful exploitation?
An authenticated user may invoke machine learning functionality outside their authorized scope and consume cluster resources they should not be able to access. The supplied severity vector indicates low availability impact and no confidentiality or integrity impact.