CVE-2026-72671

Source
https://cve.org/CVERecord?id=CVE-2026-72671
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72671.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72671
Aliases
Downstream
Published
2026-08-13T19:11:15Z
Modified
2026-09-06T08:14:57Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments
Details

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.

Database specific
{
    "cna_assigner": "elastic",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72671.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.0.0"
                },
                {
                    "last_affected": "8.19.19"
                },
                {
                    "introduced": "9.0.0"
                },
                {
                    "last_affected": "9.4.4"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "8.19.20"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.4.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v7.*
v7.0.0-alpha1
v7.0.0-alpha2
v8.*
v8.0.0-alpha1
v8.0.0-alpha2
v8.19.0
v8.19.1
v8.19.10
v8.19.11
v8.19.12
v8.19.13
v8.19.14
v8.19.15
v8.19.16
v8.19.17
v8.19.18
v8.19.19
v8.19.2
v8.19.3
v8.19.4
v8.19.5
v8.19.6
v8.19.7
v8.19.8
v8.19.9
v9.*
v9.4.0
v9.4.1
v9.4.2
v9.4.3
v9.4.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72671.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "283190670438501987514727838726815920477",
                "139872482520600089094968553951135983484",
                "244928736363048457427079246025589015191"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72671-15fc2a3d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighterTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "35973537492193988444530376691395407843",
            "length": 2369
        },
        "id": "CVE-2026-72671-3749bff4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java",
            "function": "setupParser"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "114508176030696626539066047296433779214",
                "43384607500169746049581282043376952148",
                "283563727296098110195444588655154165811",
                "277031765205288332698033581440269116720",
                "187407052376657667672985622362187421922",
                "90126549817761157374395826113896432271",
                "62431126033836515299954878706677890458",
                "276372619117036678140958072933552714348",
                "34204804071724460000309539643270206424",
                "178874689487166837173458238589286447776"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72671-56785d56",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "74600334261879604741521313242640339568",
            "length": 4662
        },
        "id": "CVE-2026-72671-687797ed",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java",
            "function": "highlight"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "10160088286724545746756661846724288313",
            "length": 176
        },
        "id": "CVE-2026-72671-6e669937",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java",
            "function": "getFieldType"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "130192812032915568189929366428112074279",
                "338587668112843751875004607897056457244",
                "311636223832287298418351940618914661904",
                "14559433973571236327103093772803942734",
                "81766092491860980139880041074416541030",
                "83778004218823664808743686188872036723",
                "217672029278899031516016760140755058444"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72671-9734acfc",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/rest/action/search/SearchCapabilities.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "243868588130949656791143692081236563864",
                "311505216586199373294314499230294889565",
                "23300629379259170631342652985157100415",
                "99779525804820300359777388439313924719",
                "124392759507223488964887386448798184793",
                "57056074566821104672192600168236166604",
                "183428232184500482658775793061523078930"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72671-bd63b83e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "122639132757664986803138175691671001655",
                "335892283999867396276535502941166644649",
                "252845685254806679929754126735709659653",
                "70459544080609156892578956654685198979",
                "288350301639674802567568120843372854348",
                "128879439556083118790804565740578695567",
                "183568503689704087885138164738553210791",
                "315988264130765396628199666193426980549",
                "110105306531665817097053229432225710351",
                "108886619290626151118397149603734671098",
                "68900764452827513161409585113073530589",
                "109699481272201296627752008736891181922",
                "89552474233322494405147063649180198152",
                "243794874480578150177830085733756836217",
                "128936352400535787295390066296206280301",
                "168193967744077208144892951303807415035",
                "32485489507345202777470620624306770167",
                "82468793747458534960176489784612968344",
                "95431536162858288727547312167888083055",
                "79895802567313409968279279144916310561",
                "109983373614664327492018760324106301607",
                "254164139643632659290414288579740637195",
                "218911482828271878345863242741149783938",
                "290149128642774742559654272690374710990",
                "129649976829885946269329561068451864187",
                "271521553609249011929656203339955131993",
                "116967678018103273313850160203491775016",
                "34507466461561024444180968955125864688",
                "149539466270008484339757108260134471872",
                "241540141246676079432554907112288153733",
                "247281622777097759942516432384261889326",
                "8682106367820934505412234917026602498",
                "258599880353756871245323998211345504441",
                "140682565192181975671989624265695960587",
                "100268892565605616091333444189761449681",
                "214950598829781998119271592022997186976",
                "200550104524719405385075838124186899375",
                "313720121068230248463194804287647092807",
                "188167255630204728049901172366742944889",
                "197051329735330186721065881872811534640",
                "246392715163119707808625433035684232434",
                "127945619089996738346525337879859203179",
                "136702270964155933380398036066653195170"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72671-ca3692e7",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "186492591955110081095185334864085897708",
            "length": 674
        },
        "id": "CVE-2026-72671-dc0a4f96",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java",
            "function": "build"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "50460798663850937323875144151113267593",
            "length": 3586
        },
        "id": "CVE-2026-72671-e5c86fee",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java",
            "function": "testBuildSearchContextHighlight"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250502453778712768962053518703255093608",
                "293745187741608286289486472330502044902",
                "92285933861987769382932879499624280339",
                "48848052402887098574079705828368727963",
                "180954780310110417851376237840132855867",
                "265701660666103015958674140349152633739",
                "219483656979539974598819100907886798376"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-72671-f6f0ec86",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
        "target": {
            "file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java"
        }
    }
]
vanir_signatures_modified
"2026-09-06T08:14:57Z"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "8.19.20"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.4.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

7.*
7.0-known-good
Other
deploy@1693594780
deploy@1693609987
deploy@1693853982
deploy@1693860790
deploy@1693866333
deploy@1694087994
deploy@1694162455
deploy@1694506029
deploy@1694683198
deploy@1695286747
deploy@1696328885
deploy@1696415195
deploy@1696508231
deploy@1696618725
deploy@1696873111
deploy@1697028216
deploy@1697232175
deploy@1697564183
deploy@1698046713
deploy@1698657637
deploy@1699260155
deploy@1699865290
deploy@1700491293
deploy@1701160888
deploy@1701687168
deploy@1702284899
deploy@1702367069
deploy@1702879551
deploy@1702903357
deploy@1703484304
deploy@1704089101
deploy@1704693922
deploy@1705298718
deploy@1705306975
deploy@1705903520
deploy@1706508321
deploy@1707113127
deploy@1707717945
deploy@1708322739
deploy@1708927574
deploy@1709532332
deploy@1709533819
deploy@1710137117
deploy@1710146776
deploy@1710741924
deploy@1711370131
deploy@1711952105
deploy@1712566963
deploy@1713161715
deploy@1713766425
deploy@1714371303
deploy@1714976069
deploy@1715580861
deploy@1716185667
deploy@1716790412
deploy@1716800745
deploy@1717395230
deploy@1717401777
deploy@1718000036
deploy@1718616070
deploy@1719209622
deploy@1719814351
deploy@1720419201
deploy@1721023892
deploy@1721628835
deploy@1722233551
deploy@1722838314
deploy@1723443177
deploy@1724047965
deploy@1724652827
deploy@1725257503
deploy@1725862301
deploy@1726473511
deploy@1727071987
deploy@1727676838
deploy@1728281754
deploy@1728886420
deploy@1729491328
deploy@1730095989
deploy@1730700921
deploy@1731305644
deploy@1731910526
deploy@1732515196
deploy@1733120035
deploy@1733724770
deploy@1734329529
deploy@1734934371
deploy@1735539127
deploy@1736144018
deploy@1736748791
deploy@1737353792
deploy@1737958429
deploy@1738563299
deploy@1739168190
deploy@1739772912
deploy@1740377517
deploy@1740982600
deploy@1741587091
deploy@1742191921
deploy@1742796690
deploy@1743401509
deploy@1744006300
deploy@1744611164
deploy@1745272860
deploy@1745820726
deploy@1746425571
deploy@1747030444
deploy@1747635089
deploy@1748239962
deploy@1748844884
deploy@1748942782
deploy@1749449628
deploy@1750054502
deploy@1750659199
deploy@1751264043
deploy@1751277018
deploy@1751868905
deploy@1752473612
deploy@1753078461
deploy@1753683246
deploy@1754288252
deploy@1754931892
deploy@1755497723
deploy@1756102496
deploy@1756707119
deploy@1757311879
deploy@1757916930
deploy@1758521525
deploy@1759126366
deploy@1759731406
deploy@1760335957
deploy@1761545598
deploy@1762150324
deploy@1762755325
deploy@1763360043
deploy@1763964909
deploy@1764659574
deploy@1765174614
deploy@1765779173
deploy@1766384231
deploy@1766988978
deploy@1767593647
deploy@1768198527
deploy@1768218634
deploy@1768803256
deploy@1769408156
deploy@1770012923
deploy@1770617847
deploy@1771222690
deploy@1771827228
deploy@1772432307
deploy@1773036835
deploy@1773641703
deploy@1773858623
deploy@1774246725
deploy@1774851440
deploy@1775456092
test-depl-20231013154558
test-depl-20231025084603
v4.*
v4.0.0-beta1
v4.0.0-beta1.1
v4.0.0-beta2
v4.0.0-beta3
v4.2.0-beta1
v5.*
v5.0.0-alpha5
v6.*
v6.0.0-alpha1
v6.0.0-alpha2
v7.*
v7.0.0-alpha1
v8.*
v8.0.0-alpha1
v8.0.0-alpha2
v8.19.0
v8.19.1
v8.19.10
v8.19.11
v8.19.12
v8.19.13
v8.19.14
v8.19.15
v8.19.16
v8.19.17
v8.19.18
v8.19.19
v8.19.2
v8.19.3
v8.19.4
v8.19.5
v8.19.6
v8.19.7
v8.19.8
v8.19.9
v9.*
v9.4.0
v9.4.1
v9.4.2
v9.4.3
v9.4.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72671.json"