CVE-2026-72654: Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosur
Summary
A vulnerability in Kibana's machine learning feature allows users with only read access to view data they shouldn't have permission to see. The problem occurs because an operation runs with elevated internal service permissions instead of the user's actual permissions, letting attackers access unauthorized information from Elasticsearch (a data storage system) without needing special cluster or index privileges.
Vulnerability Details
6.5(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
network
low
low
none
September 1, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72654
First tracked: September 1, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 75%