PatchSiren cyber security CVE debrief
CVE-2026-72675 Elastic CVE debrief
The CVE-2026-72675 record describes a Missing Authorization vulnerability in Kibana's Machine Learning functionality, which can lead to cross-space information disclosure and unauthorized data modification. This issue arises because Kibana Machine Learning operations are carried out with elevated internal permissions and rely on a per-request space filter to keep machine learning data separated across different spaces. However, part of the Machine Learning functionality did not apply this filter, allowing operations from one space to be carried out against the machine learning data of every space in the deployment. Organizations using Kibana, especially those with sensitive data or multiple spaces, should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-13T20:17:28.137Z and has not been modified since then.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-02
Who should care
Organizations using Kibana, especially those with sensitive data or multiple spaces, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing the configurations of their Kibana deployments, ensuring proper authorization and access controls are in place, and monitoring for suspicious activity. Additionally, organizations should prioritize patching to prevent potential data exposure and unauthorized modifications. Security teams and vulnerability management teams should also be aware of the potential impact of this vulnerability on their assets and take appropriate measures to protect them. This may involve coordinating with vendors for patches, implementing compensating controls, and verifying the effectiveness of these measures. Asset owners and operators should also be informed about the potential risks and take necessary actions to secure their environments. This vulnerability can be mitigated by applying patches or updates provided by the vendor, reviewing and adjusting configurations, and implementing additional security measures. It is essential for organizations to assess their exposure and take appropriate actions to prevent exploitation. This may involve reviewing Kibana logs, monitoring Machine Learning operations, and implementing network segmentation or access controls to limit potential damage. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their sensitive data. The CVE record indicates that the vulnerability has not been modified since its publication on 2026-08-13T20:17:28.137Z, emphasizing the need for prompt action to mitigate the vulnerability. The vulnerability's impact can be significant, and organizations should not delay in addressing it. They should also consider the potential operational impact of this vulnerability on their environments and take steps to minimize it. This may involve coordinating with vendors, implementing compensating controls, and verifying the effectiveness of these measures. By prioritizing patching and taking proactive steps to secure their environments, organizations can reduce the risk associated with this vulnerability and
Technical summary
The vulnerability is caused by a missing authorization check in Kibana's Machine Learning functionality. This allows an attacker to perform operations on machine learning data across different spaces, potentially leading to information disclosure and unauthorized data modification. Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment. This issue can be mitigated by applying patches or updates provided by the vendor to address the vulnerability, reviewing and adjusting Kibana configurations to ensure proper authorization and access controls, monitoring Kibana logs and Machine Learning operations for suspicious activity, and implementing additional security measures such as network segmentation or access controls to limit potential damage.
Defensive priority
Organizations using Kibana should prioritize patching to prevent potential data exposure and unauthorized modifications.
Recommended defensive actions
- Apply patches or updates provided by the vendor to address the vulnerability
- Review and adjust Kibana configurations to ensure proper authorization and access controls
- Monitor Kibana logs and Machine Learning operations for suspicious activity
- Implement additional security measures, such as network segmentation or access controls, to limit potential damage
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record indicates a Missing Authorization vulnerability in Kibana, which can lead to cross-space information disclosure and unauthorized data modification. Kibana Machine Learning operations are carried out with elevated internal permissions and rely on a per-request space filter. However, part of the Machine Learning functionality did not apply this filter, allowing operations from one space to be carried out against the machine learning data of every space in the deployment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72675 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72675
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72675 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72675
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-92/389526
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.