6.5

CVE-2026-72654

Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elastic ≫ Kibana Version >= 8.0.0 < 8.19.21
Elastic ≫ Kibana Version >= 9.0.0 < 9.4.6
Elastic ≫ Kibana Version >= 9.5.0 < 9.5.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.275
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@elastic.co 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-250 Execution with Unnecessary Privileges

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-135/390091
Vendor Advisory