CVE-2026-72671
EUVD-2026-5825813.08.2026, 20:17
A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 𝑥 < 8.19.20 |
| elastic | kibana | 9.0.0 ≤ 𝑥 < 9.4.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration