Authorization bypass through user-controlled key in Kibana - CVE-2026-72629
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose inference output from a trained model in a different space and cause a denial of service by stopping or altering resources for an active trained model deployment in another space.
The vulnerability exists due to authorization bypass through user-controlled key in machine learning trained model and deployment operations when handling cross-space access requests. A remote user can supply a user-controlled key to access model inference output or stop or update a deployment in another space to disclose inference output from a trained model in a different space and cause a denial of service by stopping or altering resources for an active trained model deployment in another space.
The issue affects functionality that is not properly constrained by ACLs across spaces.