Authorization Bypass in Kibana by Elastic
CVE-2026-72629

7.1HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72629?

A vulnerability in Kibana allows an attacker to bypass authorization controls through user-controlled keys. This can lead to unauthorized access to functionalities that are not properly restricted by Access Control Lists (ACLs). As a result, users may disclose sensitive inference outputs from models in spaces they are not permitted to access. Additionally, this flaw can impact operations such as stopping or updating active model deployments in unauthorized spaces, potentially altering their allocated resources.

Affected Version(s)

Kibana 8.19.0 <= 8.19.19

Kibana 9.0.0 <= 9.4.4

Kibana 9.5.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.