PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72675 Elastic CVE debrief

The CVE-2026-72675 record describes a Missing Authorization vulnerability in Kibana's Machine Learning functionality, which can lead to cross-space information disclosure and unauthorized data modification. This issue arises because Kibana Machine Learning operations are carried out with elevated internal permissions and rely on a per-request space filter to keep machine learning data separated across different spaces. However, part of the Machine Learning functionality did not apply this filter, allowing operations from one space to be carried out against the machine learning data of every space in the deployment. Organizations using Kibana, especially those with sensitive data or multiple spaces, should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-13T20:17:28.137Z and has not been modified since then.

Vendor
Elastic
Product
Kibana
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-02
Advisory published
2026-08-13
Advisory updated
2026-09-02

Who should care

Organizations using Kibana, especially those with sensitive data or multiple spaces, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing the configurations of their Kibana deployments, ensuring proper authorization and access controls are in place, and monitoring for suspicious activity. Additionally, organizations should prioritize patching to prevent potential data exposure and unauthorized modifications. Security teams and vulnerability management teams should also be aware of the potential impact of this vulnerability on their assets and take appropriate measures to protect them. This may involve coordinating with vendors for patches, implementing compensating controls, and verifying the effectiveness of these measures. Asset owners and operators should also be informed about the potential risks and take necessary actions to secure their environments. This vulnerability can be mitigated by applying patches or updates provided by the vendor, reviewing and adjusting configurations, and implementing additional security measures. It is essential for organizations to assess their exposure and take appropriate actions to prevent exploitation. This may involve reviewing Kibana logs, monitoring Machine Learning operations, and implementing network segmentation or access controls to limit potential damage. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their sensitive data. The CVE record indicates that the vulnerability has not been modified since its publication on 2026-08-13T20:17:28.137Z, emphasizing the need for prompt action to mitigate the vulnerability. The vulnerability's impact can be significant, and organizations should not delay in addressing it. They should also consider the potential operational impact of this vulnerability on their environments and take steps to minimize it. This may involve coordinating with vendors, implementing compensating controls, and verifying the effectiveness of these measures. By prioritizing patching and taking proactive steps to secure their environments, organizations can reduce the risk associated with this vulnerability and

Technical summary

The vulnerability is caused by a missing authorization check in Kibana's Machine Learning functionality. This allows an attacker to perform operations on machine learning data across different spaces, potentially leading to information disclosure and unauthorized data modification. Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment. This issue can be mitigated by applying patches or updates provided by the vendor to address the vulnerability, reviewing and adjusting Kibana configurations to ensure proper authorization and access controls, monitoring Kibana logs and Machine Learning operations for suspicious activity, and implementing additional security measures such as network segmentation or access controls to limit potential damage.

Defensive priority

Organizations using Kibana should prioritize patching to prevent potential data exposure and unauthorized modifications.

Recommended defensive actions

  • Apply patches or updates provided by the vendor to address the vulnerability
  • Review and adjust Kibana configurations to ensure proper authorization and access controls
  • Monitor Kibana logs and Machine Learning operations for suspicious activity
  • Implement additional security measures, such as network segmentation or access controls, to limit potential damage
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record indicates a Missing Authorization vulnerability in Kibana, which can lead to cross-space information disclosure and unauthorized data modification. Kibana Machine Learning operations are carried out with elevated internal permissions and rely on a per-request space filter. However, part of the Machine Learning functionality did not apply this filter, allowing operations from one space to be carried out against the machine learning data of every space in the deployment.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72675 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72675

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72675 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72675

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-92/389526

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.