Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic kibana |
|
| Vendors & Products |
Elastic
Elastic kibana |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required. | |
| Title | Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure | |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-01T19:42:05.466Z
Reserved: 2026-08-10T11:17:38.893Z
Link: CVE-2026-72654
Updated: 2026-09-01T19:42:00.776Z
Status : Awaiting Analysis
Published: 2026-09-01T20:17:17.093
Modified: 2026-09-01T21:15:37.123
Link: CVE-2026-72654
No data.
OpenCVE Enrichment
Updated: 2026-09-02T01:45:05Z
-
CWE-250
Execution with Unnecessary Privileges