---
id: CVE-2026-72671
title: >-
  A Kibana Machine Learning capability that removes a saved object from the
  current space accepts machine learning trained models as a target, but it
  verifies only the privileges that apply to anomaly detection jobs and data
  frame analytic…
summary: >-
  A Kibana Machine Learning capability that removes a saved object from the
  current space accepts machine learning trained models as a target, but it
  verifies only the privileges that apply to anomaly detection jobs and data
  frame analytic…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
vendor: elastic
product: kibana
affected:
  - kibana < 8.19.20
  - 'kibana >= 9.0.0, < 9.4.5'
patched:
  - kibana 9.4.5
published: '2026-08-13'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72671'
references:
  - url: >-
      https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-88/389525
    label: security@elastic.co
tags:
  - nvd
epss: 0.00268
epssPercentile: 0.16843
ingestedAt: '2026-09-05T18:43:14.447Z'
---

## Overview

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.

## Affected

- `kibana < 8.19.20`
- `kibana >= 9.0.0, < 9.4.5`

## Remediation

Upgrade past the affected range:

- `kibana 9.4.5`
