Missing Authorization in Kibana - CVE-2026-72675
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify data across spaces.
The vulnerability exists due to missing authorization in Kibana Machine Learning when handling machine learning operations across spaces. A remote user can issue requests from one space to access or modify machine learning data belonging to other spaces to disclose sensitive information and modify data across spaces.
Part of the functionality failed to apply the per-request space filter while using elevated internal Elasticsearch permissions.