CVE-2026-72675
Kibana vulnerability analysis and mitigation

Overview

CVE-2026-72675 is a Missing Authorization vulnerability (CWE-862) in Elastic Kibana's Machine Learning functionality that enables cross-space information disclosure and unauthorized data modification. Kibana Machine Learning executes Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to isolate data between spaces; part of the ML functionality failed to apply this filter, allowing operations from one space to affect ML data across all spaces in the deployment. Affected versions include Kibana 8.0.0 through 8.19.19 and 9.0.0 through 9.4.4. The vulnerability was published on August 13, 2026, with a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Elastic Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): Kibana's Machine Learning subsystem operates with elevated internal Elasticsearch permissions and uses per-request space filters to enforce data isolation between Kibana spaces. A subset of ML functionality omitted the application of this space filter, meaning that ML operations initiated from one space were executed against the ML data of all spaces in the deployment — effectively bypassing the intended access control boundary. This constitutes a Privilege Abuse pattern (CAPEC-122), where a low-privileged authenticated user can leverage the ML subsystem's elevated permissions to read or modify data outside their authorized scope. No special configuration is required to trigger the flaw; any authenticated user with network access to Kibana and low-level privileges can exploit it (GitHub Advisory, Elastic Advisory).

Impact

Successful exploitation allows any low-privileged authenticated user to read machine learning data from all Kibana spaces in the deployment, resulting in high confidentiality impact. Additionally, the attacker can modify ML data (e.g., jobs, configurations, results) across spaces beyond their authorized scope, resulting in low integrity impact. Availability is not affected. In multi-tenant or enterprise Kibana deployments where spaces are used to segregate sensitive data between teams or business units, this vulnerability can expose confidential ML models, anomaly detection results, and associated Elasticsearch data to unauthorized parties (GitHub Advisory, Elastic Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.215% (12th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid low-privileged Kibana account and network access, but no user interaction or complex conditions (GitHub Advisory).

Mitigation and workarounds

Elastic has released patched versions addressing this vulnerability: Kibana 8.19.20 and Kibana 9.4.5. Users should upgrade to one of these versions immediately. As interim measures, restrict network access to Kibana to only authorized and trusted users, and review machine learning data access logs for any anomalous cross-space data access or unexpected modifications. Consider implementing additional network segmentation and access controls to limit which users can reach Kibana's Machine Learning features (Elastic Advisory).

Community reactions

Elastic published a security advisory (ESA-2026-92) on August 13, 2026, disclosing the vulnerability and providing patched versions. The NetEye blog published a security advisory on August 14, 2026, noting the impact on Elastic Stack 8 deployments. Threat intelligence aggregators including Tenable, VulDB, and offseq.com radar tracked the vulnerability shortly after disclosure, but no significant researcher commentary or social media discussion has been observed beyond routine CVE tracking (Elastic Advisory).

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72677HIGH7.3
  • Kibana logoKibana
  • kibana-8.19
NoYesAug 13, 2026
CVE-2026-72675HIGH7.1
  • Kibana logoKibana
  • kibana-8.19
NoYesAug 13, 2026
CVE-2026-72681MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72680MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72674MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.3
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management