CVE-2026-72671: A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained
mediumvulnerability
security
Summary
A security flaw in Kibana (Elastic's data visualization tool) Machine Learning allows users to remove trained models (pre-built AI models) from a workspace if they have permission to create certain types of jobs, even if they shouldn't have that permission. The actual model isn't deleted and can be restored by someone with proper access, but this is still a privilege escalation vulnerability (a situation where someone gains more control than they should have).
Vulnerability Details
CVSS Score
4.3(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
network
Attack Complexity
low
Privileges Required
low
User Interaction
none
Disclosure Date
August 13, 2026
Classification
Attack SophisticationTrivial
Impact (CIA+S)
integrity
AI Component TargetedModel
Affected Vendors
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72671
First tracked: August 13, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%