Junglewise Threat Intelligence

CVE-2026-72629: Elastic Kibana authorization bypass in machine learning models

CVE-2026-72629 · Severity: high · CVSS 7.1 · Published 2026-08-13

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is Elastic's analytics and visualization platform used to explore and monitor data in the Elastic Stack. An authorization flaw allows authenticated users to bypass access controls and interact with machine learning trained models in spaces they should not have permission to access, including viewing model inference output, stopping active deployments, or modifying resource allocation. This could expose sensitive model behavior or disrupt ML operations across the organization.

Technical details

The vulnerability is an authorization bypass through user-controlled keys (CWE-639) in Kibana's machine learning functionality. Authenticated users can exploit inadequate ACL enforcement (CAPEC-1) to access trained models and deployments in different spaces outside their permission scope. The attack vector is network-based and requires valid Kibana credentials (PR:L) but no user interaction. An attacker can disclose inference output from unauthorized models, stop active model deployments, or alter their resource allocation. The issue is patched in Kibana versions 8.19.20, 9.4.5, and 9.5.1; no workarounds are available for unpatched systems.

Affected products

  • Elastic Kibana 8.19.0 to 8.19.19, 9.0.0 to 9.4.4, 9.5.0

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: Fixed in versions 8.19.20, 9.4.5, and 9.5.1

References

Related threats