CVE-2026-72675: Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modificat
Summary
Kibana (a data visualization tool) has a missing authorization bug where its Machine Learning feature doesn't properly filter data between spaces (isolated work areas). This means operations from one space could access and modify machine learning data from all other spaces in the system, causing unauthorized information disclosure and data changes.
Vulnerability Details
7.1(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
network
low
low
none
August 13, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72675
First tracked: August 13, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 75%