Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic kibana |
|
| Vendors & Products |
Elastic
Elastic kibana |
|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user. | |
| Title | Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-08-13T20:33:05.978Z
Reserved: 2026-08-10T11:17:49.704Z
Link: CVE-2026-72671
Updated: 2026-08-13T20:33:01.763Z
Status : Received
Published: 2026-08-13T20:17:27.653
Modified: 2026-08-13T21:18:11.500
Link: CVE-2026-72671
No data.
OpenCVE Enrichment
Updated: 2026-08-13T22:15:03Z
-
CWE-862
Missing Authorization