
CyberSec Daily ✓ · 📊 SIEM security · August 13, 2026 🎯 High-severity Kibana flaw exposes machine-learning data across spaces Elastic disclosed CVE-2026-72675, a missing-authorization vulnerability in Kibana Machine Learning. A low-privileged user could potentially view or modify ML data belonging to other Kibana spaces. The issue affects Kibana 8.0.0–8.19.19 and 9.0.0–9.4.4. It is fixed in 8.19.20 and 9.4.5. Elastic says no workaround is available. 🔗 Source: Elastic security advisory #Kibana #ElasticSecurity #CVE202672675 #SIEM #SOC
Post summary
Elastic disclosed CVE‑2026‑72675, a missing‑authorization vulnerability in Kibana Machine Learning that lets low‑privileged users access or modify data across spaces; the flaw is fixed in newer releases.
