Junglewise Threat Intelligence

CVE-2026-72654: Elastic Kibana privilege escalation in machine learning feature

CVE-2026-72654 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana's machine learning feature performs certain read operations using an internal service identity instead of the requesting user's own identity. This allows users with read-only access to the machine learning feature to view Elasticsearch data from indices they are not authorized to access, potentially exposing sensitive business or customer information. No special Elasticsearch privileges are required to exploit this vulnerability.

Technical details

The vulnerability is a privilege escalation flaw (CWE-250) in Kibana's machine learning module where operations that should execute with the requesting user's identity are instead performed with an internal service account identity. The attack vector is network-based and requires only low privileges (read access to the ML feature) and user login; no additional authentication or Elasticsearch cluster/index privileges are needed. An authenticated attacker can retrieve unauthorized data from Elasticsearch indices, leading to information disclosure (confidentiality impact). The issue affects Kibana 8.0.0–8.19.20, 9.0.0–9.4.5, and 9.5.0–9.5.1, and is fixed in versions 8.19.21, 9.4.6, and 9.5.2. No workarounds are available.

Affected products

  • Elastic Kibana 8.0.0 through 8.19.20, 9.0.0 through 9.4.5, 9.5.0 through 9.5.1

Timeline

  • 2026-09-01: disclosed: Vulnerability disclosed in ESA-2026-135
  • 2026-09-01: patched: Fixed in Kibana 8.19.21, 9.4.6, 9.5.2

References

Related threats