CVE-2026-82293: Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-18...

Added to the CISA Known Exploited Vulnerabilities catalog on 02 Sep 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 4.3.

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization sco...

Required action: Review and patch if applicable to your AI infrastructure.