Execution with unnecessary privileges in Kibana - CVE-2026-72654

 

Execution with unnecessary privileges in Kibana - CVE-2026-72654

Published: September 1, 2026


Vulnerability identifier: #VU146647
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72654
CWE-ID: CWE-250
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to execution with unnecessary privileges in the Kibana machine learning feature when performing an operation available to users with read access to the machine learning feature. A remote user can invoke the operation to disclose sensitive information.

No Elasticsearch cluster or index privileges are required.


Affected software

Kibana

How to mitigate CVE-2026-72654

Install security update from vendor's website.

Kibana - addressed in versions 8.19.21, 9.4.6, 9.5.2

External References

Related Security Bulletins