{"data":{"id":"549dbfcb-ab37-42f7-ba20-9a5ed6e90604","title":"CVE-2026-72654: Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosur","summary":"A vulnerability in Kibana's machine learning feature allows users with only read access to view data they shouldn't have permission to see. The problem occurs because an operation runs with elevated internal service permissions instead of the user's actual permissions, letting attackers access unauthorized information from Elasticsearch (a data storage system) without needing special cluster or index privileges.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72654","publishedAt":"2026-09-01T20:17:17.093Z","cveId":"CVE-2026-72654","cweIds":["CWE-250"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Elastic","Kibana"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-01T20:17:17.093Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}