Authorization bypass through user-controlled key in Kibana - CVE-2026-72629

 

Authorization bypass through user-controlled key in Kibana - CVE-2026-72629

Published: August 13, 2026


Vulnerability identifier: #VU142355
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72629
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose inference output from a trained model in a different space and cause a denial of service by stopping or altering resources for an active trained model deployment in another space.

The vulnerability exists due to authorization bypass through user-controlled key in machine learning trained model and deployment operations when handling cross-space access requests. A remote user can supply a user-controlled key to access model inference output or stop or update a deployment in another space to disclose inference output from a trained model in a different space and cause a denial of service by stopping or altering resources for an active trained model deployment in another space.

The issue affects functionality that is not properly constrained by ACLs across spaces.


Affected software

Kibana

How to mitigate CVE-2026-72629

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.5, 9.5.1

External References

Related Security Bulletins