Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster resources they should not be able to reach. | |
| Title | Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-02T15:58:10.881Z
Reserved: 2026-08-28T11:30:29.847Z
Link: CVE-2026-82293
Updated: 2026-09-02T15:49:46.946Z
Status : Received
Published: 2026-09-02T15:17:43.157
Modified: 2026-09-02T16:17:26.123
Link: CVE-2026-82293
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization