Execution with unnecessary privileges in Kibana - CVE-2026-72654
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to execution with unnecessary privileges in the Kibana machine learning feature when performing an operation available to users with read access to the machine learning feature. A remote user can invoke the operation to disclose sensitive information.
No Elasticsearch cluster or index privileges are required.