CVE-2026-72675: Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72675?
The severity of CVE-2026-72675 is rated high with a score of 7.1.
How do I fix CVE-2026-72675?
To fix CVE-2026-72675, update to the patched version of Elastic Kibana Machine Learning provided after August 2026.
What types of vulnerabilities are associated with CVE-2026-72675?
CVE-2026-72675 is associated with missing authorization vulnerabilities that lead to cross-space information disclosure and unauthorized data modification.
What could happen if CVE-2026-72675 is exploited?
Exploitation of CVE-2026-72675 could allow an attacker to access sensitive data or modify data without proper authorization.
Which software is affected by CVE-2026-72675?
CVE-2026-72675 affects Elastic Kibana Machine Learning.