Improper Privilege Management in Kibana by Elastic
CVE-2026-72671

4.3MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72671?

A vulnerability exists in the Kibana Machine Learning feature where insufficient privilege checks allow users with roles that permit the creation of anomaly detection jobs and data frame analytics jobs to remove trained models from their current space. Although this action does not delete the models themselves, which remain accessible in other spaces, it can lead to unauthorized modifications. The situation can be reversed only by users with adequate privileges, creating potential security risks within the application's environment.

Affected Version(s)

Kibana 8.0.0 <= 8.19.19

Kibana 9.0.0 <= 9.4.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.