SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78584

MEDIUM · CVSS 4.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Kibana Osquery feature contains a vulnerability that allows authenticated users with live-query privileges to infer the existence of scheduled query identifiers in unauthorized Kibana spaces. This information disclosure could potentially expose sensitive data or system configurations. Organizations utilizing Kibana, particularly those with multiple user roles and permissions, should prioritize addressing this issue to mitigate the risk of unauthorized information exposure.

CVE
CVE-2026-78584
Severity
MEDIUM
CVSS
4.3
EPSS
0.23%

Original NVD Description

Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.

Related CVEs

Other vulnerabilities affecting the same vendor(s)