AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72671

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Kibana Machine Learning feature, allowing users with limited privileges to remove trained models from a space without proper authorization. This could lead to unauthorized modifications of machine learning resources, impacting the integrity of anomaly detection and data frame analytics jobs. Organizations utilizing Kibana for machine learning should prioritize addressing this issue to safeguard their model management processes.

CVE
CVE-2026-72671
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.