Skip to main content
EPSS 0.3%top 78%

Elk: Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification (CVE-2026-72675)

0
High
Published: 08/19/2026 (08/19/2026, 08:40:46 UTC)
Source: GCVE Database
Product: elk

Description

A missing authorization vulnerability in Kibana Machine Learning allows operations from one space to access and modify machine learning data across all spaces in the deployment. This occurs because some Machine Learning functionality does not apply the per-request space filter intended to isolate data between spaces. The vulnerability affects Kibana versions from 8.0.0 up to but not including 8.19.20 and from 9.0.0 up to but not including 9.4.5. A patch is available to address this issue.

Affected software

Bitnamimore threats →ghsa
kibana
pkg:bitnami/kibana
Affected versions
>=8.0.0 <8.19.20>=9.0.0 <9.4.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:01:06 UTC

Technical Analysis

CVE-2026-72675 is a missing authorization vulnerability in Kibana Machine Learning where Elasticsearch operations are executed with elevated internal permissions. The system relies on a per-request space filter to segregate machine learning data by space, but part of the functionality failed to apply this filter, resulting in cross-space information disclosure and unauthorized data modification. This privilege abuse vulnerability allows an attacker with access to one space to perform operations affecting data in all spaces within the deployment.

Potential Impact

An attacker with access to one Kibana space can access and modify machine learning data belonging to other spaces, violating data confidentiality and integrity boundaries. This can lead to unauthorized disclosure of sensitive information and unauthorized changes to data across multiple spaces in the Kibana deployment.

Mitigation Recommendations

A patch is available for this vulnerability. Users should upgrade affected Kibana versions to fixed releases at or beyond 8.19.20 and 9.4.5. Since this is not a cloud service, remediation requires applying the official fix. No additional vendor advisory content was provided, so check the vendor's official security advisories for exact patch versions and instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BIT-kibana-2026-72675
Osv Schema Version
1.6.2
Aliases
["CVE-2026-72675"]
Ecosystems
["Bitnami"]
Database Specific Severity
High
State
PUBLISHED

Threat ID: 6a85b4aaacd9273b49250eda

Added to database: 08/19/2026, 13:50:34 UTC

Last enriched: 08/19/2026, 14:01:06 UTC

Last updated: 10/04/2026, 10:04:21 UTC

Views: 59

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses