<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:26:47.353252+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-elk-2026-72671</id>
    <title>BIT-elk-2026-72671 — Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments</title>
    <updated>2026-10-02T17:26:47.431617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: elk</p>
<p>A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-elk-2026-72671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1020</id>
    <title>certfr-2026-avi-1020 — De multiples vulnérabilités ont été découvertes dans Elastic Kibana. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-02T17:26:47.431681+00:00</updated>
    <content>certfr-2026-avi-1020</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352348</id>
    <title>EUVD-2026-352348</title>
    <updated>2026-10-02T17:26:47.431703+00:00</updated>
    <content>EUVD-2026-352348</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72671</id>
    <title>fkie_cve-2026-72671</title>
    <updated>2026-10-02T17:26:47.431716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-72671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-92c8-vpgp-w44c</id>
    <title>GHSA-92c8-vpgp-w44c</title>
    <updated>2026-10-02T17:26:47.431740+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-92c8-vpgp-w44c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2824</id>
    <title>WID-SEC-W-2026-2824 — Kibana: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:26:47.431756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um vertrauliche Informationen einschließlich Zugangsdaten offenzulegen, Daten und Konfigurationen zu manipulieren, Berechtigungen zu umgehen und einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2824"/>
  </entry>
</feed>
