{"id":"CVE-2026-72671","title":"A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytic…","summary":"A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytic…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"vendor":"elastic","product":"kibana","affected":["kibana < 8.19.20","kibana >= 9.0.0, < 9.4.5"],"patched":["kibana 9.4.5"],"published":"2026-08-13","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72671","references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-88/389525","label":"security@elastic.co"}],"tags":["nvd"],"epss":0.00196,"epssPercentile":0.09544,"ingestedAt":"2026-09-05T18:43:14.447Z","slug":"CVE-2026-72671","body":"## Overview\n\nA Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.\n\n## Affected\n\n- `kibana < 8.19.20`\n- `kibana >= 9.0.0, < 9.4.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `kibana 9.4.5`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}