SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72654

MEDIUM · CVSS 6.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Kibana machine learning feature contains a vulnerability that allows users with only read access to execute operations using an internal service identity, potentially leading to unauthorized information disclosure from Elasticsearch indices. This privilege abuse could expose sensitive data to users who should not have access, making it critical for organizations utilizing Kibana to prioritize remediation efforts. Security teams should assess their Kibana configurations and user access controls to mitigate this risk.

CVE
CVE-2026-72654
Severity
MEDIUM
CVSS
6.5
EPSS
0.37%

Original NVD Description

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.

Related CVEs

Other vulnerabilities affecting the same vendor(s)