CVE-2026-72671: Elastic Kibana
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.
Affected products
- Elastic Kibana: before 8.19.20 (fixed in 8.19.20); from 9.0.0, before 9.4.5 (fixed in 9.4.5)
Published 2026-08-13. Last modified 2026-09-04.