4.3
CVE-2026-78584
- EPSS 0.22%
- Veröffentlicht 02.09.2026 14:43:22
- Zuletzt bearbeitet 03.09.2026 13:41:38
- Erkennungen
Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.123 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-204 Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-161/390115