CVE-2026-72654
Awaiting Analysis Awaiting Analysis - Queue

Privilege Abuse in Kibana Machine Learning Feature

Vulnerability report for CVE-2026-72654, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Elastic

Description

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
elastic kibana to 8.19.21 (exc)
elastic kibana to 9.4.6 (exc)
elastic kibana to 9.5.2 (exc)
elastic kibana *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves unnecessary privilege execution in Kibana's machine learning feature. A read-only user could perform an operation using an internal service identity instead of their own, potentially accessing unauthorized Elasticsearch indices.

Detection Guidance

Check Kibana version with command: curl -XGET http://localhost:5601/api/console/api_server?path=%2F&method=GET. If running versions 8.19.20 or earlier, 9.4.5 or earlier, or 9.5.1 or earlier, the system is vulnerable.

Impact Analysis

An attacker with read access to Kibana's machine learning feature could exploit this to view data from Elasticsearch indices they are not permitted to access, leading to unauthorized information disclosure.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected Kibana versions may face compliance violations if exploited.

Mitigation Strategies

Upgrade Kibana to versions 8.19.21, 9.4.6, or 9.5.2 immediately. No workarounds exist for users unable to upgrade. Verify upgrade completion by rechecking the version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72654. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart