
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-72675 is a Missing Authorization vulnerability (CWE-862) in Elastic Kibana's Machine Learning functionality that enables cross-space information disclosure and unauthorized data modification. Kibana Machine Learning executes Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to isolate data between spaces; part of the ML functionality failed to apply this filter, allowing operations from one space to affect ML data across all spaces in the deployment. Affected versions include Kibana 8.0.0 through 8.19.19 and 9.0.0 through 9.4.4. The vulnerability was published on August 13, 2026, with a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Elastic Advisory).
The root cause is CWE-862 (Missing Authorization): Kibana's Machine Learning subsystem operates with elevated internal Elasticsearch permissions and uses per-request space filters to enforce data isolation between Kibana spaces. A subset of ML functionality omitted the application of this space filter, meaning that ML operations initiated from one space were executed against the ML data of all spaces in the deployment — effectively bypassing the intended access control boundary. This constitutes a Privilege Abuse pattern (CAPEC-122), where a low-privileged authenticated user can leverage the ML subsystem's elevated permissions to read or modify data outside their authorized scope. No special configuration is required to trigger the flaw; any authenticated user with network access to Kibana and low-level privileges can exploit it (GitHub Advisory, Elastic Advisory).
Successful exploitation allows any low-privileged authenticated user to read machine learning data from all Kibana spaces in the deployment, resulting in high confidentiality impact. Additionally, the attacker can modify ML data (e.g., jobs, configurations, results) across spaces beyond their authorized scope, resulting in low integrity impact. Availability is not affected. In multi-tenant or enterprise Kibana deployments where spaces are used to segregate sensitive data between teams or business units, this vulnerability can expose confidential ML models, anomaly detection results, and associated Elasticsearch data to unauthorized parties (GitHub Advisory, Elastic Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.215% (12th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid low-privileged Kibana account and network access, but no user interaction or complex conditions (GitHub Advisory).
Elastic has released patched versions addressing this vulnerability: Kibana 8.19.20 and Kibana 9.4.5. Users should upgrade to one of these versions immediately. As interim measures, restrict network access to Kibana to only authorized and trusted users, and review machine learning data access logs for any anomalous cross-space data access or unexpected modifications. Consider implementing additional network segmentation and access controls to limit which users can reach Kibana's Machine Learning features (Elastic Advisory).
Elastic published a security advisory (ESA-2026-92) on August 13, 2026, disclosing the vulnerability and providing patched versions. The NetEye blog published a security advisory on August 14, 2026, noting the impact on Elastic Stack 8 deployments. Threat intelligence aggregators including Tenable, VulDB, and offseq.com radar tracked the vulnerability shortly after disclosure, but no significant researcher commentary or social media discussion has been observed beyond routine CVE tracking (Elastic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."