CVE-2026-78584CWE-204

CVE-2026-78584

Medium · published September 2, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
12.3
In the wild
Unconfirmed
What it is

Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00219 · 12.3th percentile
Weakness
CWE-204 · Observable Response Discrepancy
Published
2026-09-02T19:17Z
Affected products (1)
ProductVersionsFixed in
elastic/kibana≥ 9.4.0, < 9.4.49.4.4
References (1)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 14:43Z
    Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
    cvelistv5