Maybe you have a knowledge object that has no entry in the corresponding meta file. Look in the user's directory at
$SPLUNK_HOME/etc/users/USERNAME/search/local/props.conf (or maybe transforms.conf)
for the field extraction and its corresponding permissions entry. You could manually delete them both...
But when manually editing, be sure to keep the .conf file in sync with the corresponding meta file. Otherwise, weird stuff can happen, especially when you try to edit the knowledge object in the Splunk UI.