PT-2026-71781 · Elastic · Kibana

CVE-2026-72671

·

Published

2026-08-13

·

Updated

2026-08-19

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description A Kibana Machine Learning capability that removes a saved object from the current space incorrectly verifies privileges when targeting machine learning trained models. It only checks for privileges associated with anomaly detection jobs and data frame analytics jobs. Consequently, a user with permissions to create these jobs, but lacking the specific trained model privilege, can remove a trained model from a space. This action does not delete the model itself, as it remains available in other spaces, and the change can be reversed by a user with appropriate privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-72671
BIT-KIBANA-2026-72671
CVE-2026-72671

Affected Products

Kibana