CVE-2026-72629: Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the deployment stop and deployment update operations, allowing an active trained model deployment in another space to be stopped or to have its allocated resources altered.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72629?
CVE-2026-72629 has a high severity rating of 7.1.
How can I fix CVE-2026-72629?
To fix CVE-2026-72629, ensure that proper access controls and ACLs are enforced in Kibana.
What systems are affected by CVE-2026-72629?
CVE-2026-72629 affects Elastic Kibana software.
What impact does CVE-2026-72629 have on data security?
CVE-2026-72629 can lead to unauthorized access and disclosure of sensitive inference outputs from machine learning models.
When was CVE-2026-72629 published?
CVE-2026-72629 was published on August 13, 2026.