Missing Authorization in Kibana - CVE-2026-72675

 

Missing Authorization in Kibana - CVE-2026-72675

Published: August 13, 2026


Vulnerability identifier: #VU142344
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72675
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify data across spaces.

The vulnerability exists due to missing authorization in Kibana Machine Learning when handling machine learning operations across spaces. A remote user can issue requests from one space to access or modify machine learning data belonging to other spaces to disclose sensitive information and modify data across spaces.

Part of the functionality failed to apply the per-request space filter while using elevated internal Elasticsearch permissions.


Affected software

Kibana

How to mitigate CVE-2026-72675

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.5

External References

Related Security Bulletins