CVE-2026-72654CWE-250

CVE-2026-72654

Medium · published September 2, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
27.5
In the wild
Unconfirmed
What it is

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00346 · 27.5th percentile
Weakness
CWE-250 · Execution with Unnecessary Privileges
Published
2026-09-02T00:17Z
Affected products (3)
ProductVersionsFixed in
elastic/kibana≥ 8.0.0, < 8.19.218.19.21
elastic/kibana≥ 9.0.0, < 9.4.69.4.6
elastic/kibana≥ 9.5.0, < 9.5.29.5.2
References (1)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 01 SEP 19:20Z
    Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure
    cvelistv5