CVE-2026-72654 | Elastic Kibana up to 8.19.20/9.4.5/9.5.1 Machine Learning unnecessary privileges (WID-SEC-2026-3145)
A vulnerability, which was classified as problematic, was found in Elastic Kibana up to 8.19.20/9.4.5/9.5.1. This affects an unknown function of the component Machine Learning. The manipulation results in execution with unnecessary privileges.
This vulnerability is reported as CVE-2026-72654. The attack can be launched remotely. No exploit exists.