CVE-2026-72675: Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modificat
Summary
Kibana (a data visualization tool) has a missing authorization bug where its Machine Learning feature doesn't properly filter data between spaces (isolated work areas). This means operations from one space could access and modify machine learning data from all other spaces in the system, causing unauthorized information disclosure and data changes.
Vulnerability Details
7.1(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
network
low
low
none
August 13, 2026
Classification
Affected Vendors
Related Issues
GHSA-382c-vx95-w3p5: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-2589: The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72675
First tracked: August 13, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 75%