Sceawere

Vulnerability Detail

CVE-2026-72675UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kibana Cross-Space Privilege Abuse Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Elastic
Product
Kibana
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-13T20:17:28.137Z",
  "pubdate": "2026-08-13T20:17:28.137Z",
  "executiveSummary": "A Missing Authorization vulnerability identified as CWE-862 affects Kibana Machine Learning, potentially leading to cross-space information disclosure and unauthorized data modification via Privilege Abuse, categorized under CAPEC-122.\nThe core impact of this security flaw allows an authenticated attacker operating within a specific Kibana space to bypass isolation boundaries and interact with machine learning data across all spaces within the deployment.\nThe affected product is Kibana, specifically impacting the Machine Learning functionality.\nThe risk implications involve a severe breach of multi-tenancy and data segregation, where sensitive cross-tenant machine learning configurations and operational data can be read or altered without authorization.\nAttacker capabilities require access to a valid Kibana space within the deployment, from which malicious or unauthorized operations can be issued against isolated spaces due to improper privilege and context enforcement.\nExploitation relies on issuing specific Elasticsearch operations through the vulnerable Machine Learning component that fails to apply the mandatory per-request space filter, effectively inheriting elevated internal permissions across the entire cluster deployment.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient authorization checks and a failure to enforce context isolation within Kibana Machine Learning functionality, mapped to CWE-862.\nKibana Machine Learning normally executes its underlying Elasticsearch operations utilizing elevated internal permissions.\nTo maintain data segregation between distinct tenants or operational environments, Kibana relies on a mandatory per-request space filter designed to restrict these operations to the originating space.\nDuring the vulnerable execution flow, a specific subset of the Machine Learning functionality fails to apply this per-request space filter.\nConsequently, when an operation is initiated from a single authorized space, the absence of the space filter causes the underlying Elasticsearch queries and mutations to be executed globally against the machine learning data of every space present in the deployment.\nThe attack vector involves interacting with the exposed Kibana Machine Learning API endpoints or interface components that utilize the deficient internal execution path.\nAn authenticated user with standard access to one space can leverage this flaw to perform Privilege Abuse (CAPEC-122), reading sensitive information or modifying data belonging to other isolated spaces.\nThe post-exploitation impact includes unauthorized cross-space information disclosure, potential corruption or unauthorized modification of machine learning jobs, detectors, and associated data streams across the entire deployment, severely compromising the integrity and confidentiality of multi-tenant environments."
}
CVE-2026-72675: Kibana Cross-Space Privilege Abuse Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere