CVE-2026-72671: A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomal...
Added to the CISA Known Exploited Vulnerabilities catalog on 13 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 4.3.
A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jo...
Required action: Review and patch if applicable to your AI infrastructure.