CVE-2026-72675: Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its ...
Added to the CISA Known Exploited Vulnerabilities catalog on 13 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 7.1.
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter...
Required action: Review and patch if applicable to your AI infrastructure.