CVE-2026-72675: Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification

Published Aug 13, 2026
·
Updated

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment.

Affected Software

3 affected components
Elastic Kibana Machine Learning
Elastic Kibana>=8.0.0<8.19.20
Elastic Kibana>=9.0.0<9.4.5

Event History

Aug 13, 2026
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-72675?

The severity of CVE-2026-72675 is rated high with a score of 7.1.

2

How do I fix CVE-2026-72675?

To fix CVE-2026-72675, update to the patched version of Elastic Kibana Machine Learning provided after August 2026.

3

What types of vulnerabilities are associated with CVE-2026-72675?

CVE-2026-72675 is associated with missing authorization vulnerabilities that lead to cross-space information disclosure and unauthorized data modification.

4

What could happen if CVE-2026-72675 is exploited?

Exploitation of CVE-2026-72675 could allow an attacker to access sensitive data or modify data without proper authorization.

5

Which software is affected by CVE-2026-72675?

CVE-2026-72675 affects Elastic Kibana Machine Learning.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203