Information Disclosure Vulnerability in Kibana by Elastic
CVE-2026-72654
6.5MEDIUM
What is CVE-2026-72654?
The Kibana machine learning feature contains a vulnerability that allows users with read access to potentially exploit privilege abuse. This occurs when an operation, requiring only read permissions, executes using an internal service identity rather than the requesting user's identity. As a result, users may access sensitive data from Elasticsearch indices they are not authorized to read, leading to significant information disclosure risks.
Affected Version(s)
Kibana 8.0.0 <= 8.19.20
Kibana 9.0.0 <= 9.4.5
Kibana 9.5.0 <= 9.5.1