Information Disclosure Vulnerability in Kibana by Elastic
CVE-2026-72654

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-72654?

The Kibana machine learning feature contains a vulnerability that allows users with read access to potentially exploit privilege abuse. This occurs when an operation, requiring only read permissions, executes using an internal service identity rather than the requesting user's identity. As a result, users may access sensitive data from Elasticsearch indices they are not authorized to read, leading to significant information disclosure risks.

Affected Version(s)

Kibana 8.0.0 <= 8.19.20

Kibana 9.0.0 <= 9.4.5

Kibana 9.5.0 <= 9.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.