Kibana 8.19.19, 9.3.8, 9.4.4 Security Update (ESA-2026-156)

Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job Data

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.

Affected Versions:

  • 8.x: All versions from 8.0.0 up to and including 8.19.18
  • 9.x:
    • All versions from 9.0.0 up to and including 9.3.7
    • All versions from 9.4.0 up to and including 9.4.3

Affected Configurations:

Deployments are affected only when Kibana spaces are in use and one or more non-administrator users have been granted machine learning job management privileges within a space.

Solutions and Mitigations:
The issue is resolved in Kibana versions 8.19.19, 9.3.8 and 9.4.4.

For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless
Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 5.4 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVE ID: CVE-2026-78598
Problem Type: CWE-863 - Incorrect Authorization
Impact: CAPEC-180 - Exploiting Incorrectly Configured Access Control Security Levels