Authorization Bypass in Kibana by Elastic
CVE-2026-72629
7.1HIGH
What is CVE-2026-72629?
A vulnerability in Kibana allows an attacker to bypass authorization controls through user-controlled keys. This can lead to unauthorized access to functionalities that are not properly restricted by Access Control Lists (ACLs). As a result, users may disclose sensitive inference outputs from models in spaces they are not permitted to access. Additionally, this flaw can impact operations such as stopping or updating active model deployments in unauthorized spaces, potentially altering their allocated resources.
Affected Version(s)
Kibana 8.19.0 <= 8.19.19
Kibana 9.0.0 <= 9.4.4
Kibana 9.5.0