CVE-2026-72671
Received Received - Intake

Kibana Machine Learning Trained Model Removal Vulnerability

Vulnerability report for CVE-2026-72671, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Elastic

Description

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
elastic kibana *
elastic kibana From 9.0.0 (inc) to 9.4.4 (inc)
elastic kibana 8.19.20
elastic kibana 9.4.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Kibana allows an authenticated user with specific machine learning privileges to remove a trained model from a space without proper authorization. The user only needs privileges to create anomaly detection jobs and data frame analytics jobs, not the trained model privilege itself. The model remains available in other spaces and can be restored by a privileged user.

Detection Guidance

To detect this vulnerability, check Kibana versions for affected releases (up to 8.19.19 or 9.0.0 to 9.4.4). Verify if users with anomaly detection or data frame analytics job creation privileges can remove trained models from spaces. No specific commands are provided, but review user role privileges and space assignments in Kibana logs.

Impact Analysis

This vulnerability could lead to unauthorized modification of machine learning trained model space assignments. While the model itself is not deleted, its removal from a space could disrupt machine learning operations or cause confusion in data analysis workflows.

Mitigation Strategies

Upgrade Kibana to versions 8.19.20 or 9.4.5 or later immediately. Ensure users have only necessary privileges, particularly restricting trained model removal permissions. Review and adjust role-based access controls to prevent unauthorized space modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72671. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart