Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the deployment stop and deployment update operations, allowing an active trained model deployment in another space to be stopped or to have its allocated resources altered.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Authorization Bypass Through User‑Controlled Key, allowing a user to bypass ACL checks and access features in Kibana that belong to a different space. This leads to disclosure of inference output from a trained model that the user is not authorized to view, exposing the model’s behavior. The same flaw also permits stopping or altering an active model deployment in another space, effectively disrupting that service.

Affected Systems

The affected vendor is Elastic; the product is Kibana. No specific version information was provided in the data, so all releases of Kibana may be impacted until a fix is issued.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, via the Kibana web interface, but the exact prerequisites are not detailed in the description. Given the potential for cross‑space data disclosure and domain disruption, the risk remains significant.

Generated by OpenCVE AI on August 13, 2026 at 20:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official patch or upgrade to a Kibana release that contains the fix for the authorization bypass issue.
  • Restrict Kibana user permissions to limit access to ML model APIs and disable cross‑space model management where possible.
  • Monitor Kibana logs for anomalous model access or stop/alter operations, and apply network segmentation to reduce exposure of Kibana to untrusted networks.

Generated by OpenCVE AI on August 13, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the deployment stop and deployment update operations, allowing an active trained model deployment in another space to be stopped or to have its allocated resources altered.
Title Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:27:37.918Z

Reserved: 2026-08-10T11:17:29.887Z

Link: CVE-2026-72629

cve-icon Vulnrichment

Updated: 2026-08-13T20:27:34.375Z

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:23.690

Modified: 2026-08-13T21:18:08.720

Link: CVE-2026-72629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:02Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key