VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-72654

CVE-2026-72654: Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosur

Published Sep 1, 2026 CVSS 6.5

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.

Affected AI Products

machine learning
Get the weekly digest. Every Monday: top AI security stories of the week. Free.