Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-72654

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 6.5


Contact Us

Shodan ® - All rights reserved