Medium · published September 2, 2026
Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.
| Product | Versions | Fixed in |
|---|---|---|
| elastic/kibana | ≥ 8.0.0, < 8.19.21 | 8.19.21 |
| elastic/kibana | ≥ 9.0.0, < 9.4.6 | 9.4.6 |
| elastic/kibana | ≥ 9.5.0, < 9.5.2 | 9.5.2 |