SB2026081368 - Multiple vulnerabilities in Kibana



SB2026081368 - Multiple vulnerabilities in Kibana

Published: August 13, 2026

Security Bulletin ID SB2026081368
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 28
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 7% Low 93%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 28 vulnerabilities.


1) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-72650)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through user-controlled key in alerting rule execution telemetry when accessing telemetry for alerting rules across Kibana spaces. A remote user can retrieve execution telemetry for spaces they are not authorized to access to disclose sensitive information.

The user must be authorized to read alerting rules in at least one Kibana space.


2) Resource exhaustion (CVE-ID: N/A)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote user with read-only privileges can trigger resource exhaustion and perform a denial of service (DoS) attack.


3) Missing Authorization (CVE-ID: CVE-2026-72661)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in an internal Kibana data retrieval capability used by Elastic Defend endpoint response actions when handling data retrieval requests. A remote user can access functionality not properly constrained by ACLs to disclose sensitive information.

The issue affects data retrieval performed with elevated internal permissions rather than the permissions of the requesting user, allowing access to endpoint response action records and corresponding response content returned by managed hosts.


4) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-72653)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the maintenance windows management functionality when processing a specially crafted, malformed payload. A remote user can submit a specially crafted, malformed payload to cause a denial of service.

Kibana becomes unresponsive for all users and does not recover without manual intervention.


5) Missing Authorization (CVE-ID: CVE-2026-72669)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and modify data.

The vulnerability exists due to missing authorization in Observability Onboarding flow state routes when handling read and update requests for onboarding state. A remote user can access onboarding flows created by other users and write arbitrary progress data to disclose sensitive information and modify data.

A tampered flow can cause the owner's onboarding view to fail with a server error.


6) Uncaught Exception (CVE-ID: CVE-2026-72660)

CWE-ID: CWE-248 - Uncaught Exception

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to an uncaught exception in the Kibana Security Solution feature set when processing specially crafted data that Kibana subsequently reads. A remote user can supply specially crafted data to cause a denial of service.

Exploitation requires an authenticated Kibana account with read access and the ability to write documents to at least one Elasticsearch index that Kibana subsequently reads.


7) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-72629)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose inference output from a trained model in a different space and cause a denial of service by stopping or altering resources for an active trained model deployment in another space.

The vulnerability exists due to authorization bypass through user-controlled key in machine learning trained model and deployment operations when handling cross-space access requests. A remote user can supply a user-controlled key to access model inference output or stop or update a deployment in another space to disclose inference output from a trained model in a different space and cause a denial of service by stopping or altering resources for an active trained model deployment in another space.

The issue affects functionality that is not properly constrained by ACLs across spaces.


8) Incorrect authorization (CVE-ID: CVE-2026-72630)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in Kibana Fleet when updating an existing integration policy. A remote user can replace the integration referenced by a stored policy and supply that integration's configuration to escalate privileges.

Exploitation requires an authenticated user with only the Elastic Defend endpoint policy management privilege.


9) Observable discrepancy (CVE-ID: CVE-2026-72632)

CWE-ID: CWE-203 - Observable discrepancy

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose Elastic Agent Elasticsearch API keys.

The vulnerability exists due to observable discrepancy in Kibana Fleet when evaluating caller-supplied filter expressions over stored API key fields. A remote user can send a short sequence of crafted requests to disclose Elastic Agent Elasticsearch API keys.

The issue arises because the agent listing capability reports the number of matching agents after evaluating the filters with Kibana's internal Elasticsearch privileges, allowing the API key value to be reconstructed one character at a time.


10) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-72659)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the Timelion visualization feature when processing a specially crafted, malformed payload. A remote user can submit a specially crafted, malformed payload to cause a denial of service.

Kibana becomes unavailable until the service is restarted.


11) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-72651)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the alerting feature when handling a specially crafted malformed payload. A remote user can submit a specially crafted malformed payload to cause a denial of service.

A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted.


12) Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-ID: CVE-2026-72655)

CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify case data without authorization.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the case management API of Elastic Security in Kibana when handling user-controlled object attributes. A remote user can manipulate user-controlled variables to modify case data without authorization.

The issue arises because object attributes accepted by the API were not subject to the same authorization enforcement applied in the user interface.


13) Incorrect authorization (CVE-ID: CVE-2026-72673)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to delete shared Synthetics private locations and disrupt availability monitoring in other spaces.

The vulnerability exists due to improper access control in the Synthetics private locations deletion functionality when handling deletion requests for private locations shared across multiple spaces. A remote user can delete a shared private location to delete shared Synthetics private locations and disrupt availability monitoring in other spaces.

Only deployments that use Synthetics private locations shared across more than one space are affected. Single-space deployments are not affected.


14) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-72663)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity in the TSVB visualization expression evaluator when processing a specially crafted, deeply nested expression. A remote user can submit a specially crafted expression to cause a denial of service.

Because the evaluation runs synchronously, a single request can consume the Kibana request-processing thread indefinitely until the service is restarted.


15) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-72666)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and execute unauthorized queries on managed hosts.

The vulnerability exists due to authorization bypass through user-controlled key in Kibana Osquery live query functionality when handling requests to run live queries across Kibana spaces. A remote user can send a crafted request to execute queries against Elastic Agents assigned to a space the user cannot access to disclose sensitive information and execute unauthorized queries on managed hosts.

Exploitation requires the ability to run Osquery live queries in at least one Kibana space.


16) Information disclosure (CVE-ID: CVE-2026-72670)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the Fleet proxy configuration when reading agent policies. A remote user can read the entire configuration of a configured Fleet proxy to disclose sensitive information.

Only instances with at least one Fleet proxy configured with credentials are vulnerable.


17) Missing Authorization (CVE-ID: CVE-2026-72671)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify machine learning trained model space assignments.

The vulnerability exists due to missing authorization in a Kibana Machine Learning capability that removes a saved object from the current space when handling requests to remove trained models from a space. A remote user can remove a trained model from a space to modify machine learning trained model space assignments.

Only Kibana deployments with the Machine Learning feature enabled are vulnerable. Exploitation requires a custom role that grants privileges to create anomaly detection jobs and data frame analytics jobs without granting the trained model privilege.


18) Missing Authorization (CVE-ID: CVE-2026-72675)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and modify data across spaces.

The vulnerability exists due to missing authorization in Kibana Machine Learning when handling machine learning operations across spaces. A remote user can issue requests from one space to access or modify machine learning data belonging to other spaces to disclose sensitive information and modify data across spaces.

Part of the functionality failed to apply the per-request space filter while using elevated internal Elasticsearch permissions.


19) Missing Authorization (CVE-ID: CVE-2026-72664)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute unauthorized endpoint response actions on managed hosts.

The vulnerability exists due to missing authorization in Kibana Elastic Security detection rule response actions when associating automated endpoint response actions with a detection rule. A remote user can create a detection rule with automated endpoint response actions to execute unauthorized endpoint response actions on managed hosts.

Exploitation requires deployments that use the Elastic Security solution with Elastic Defend agents enrolled, and the issue is triggered when the rule generates alerts.


20) Missing Authorization (CVE-ID: CVE-2026-72665)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information or modify host state.

The vulnerability exists due to missing authorization in Elastic Security detection rules and response action functionality when authoring and evaluating detection rules. A remote user can trigger Osquery or Elastic Defend response actions on enrolled agents to disclose sensitive information or modify host state.

Only deployments using the Elastic Security solution together with Osquery Manager or Elastic Defend are affected. Host-side impact requires enrolled agents.


21) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-72667)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the Observability log analysis validation capability when handling a specially crafted request. A remote user can send a specially crafted request to cause a denial of service.

A single request can trigger unbounded concurrent work and exhaust memory in the Kibana process, making the service unavailable until it is restarted.


22) Cross-site request forgery (CVE-ID: CVE-2026-72658)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to cross-site request forgery in the Vega visualization feature when rendering a specially crafted visualization. A remote user can save a specially crafted Vega visualization to escalate privileges.

User interaction is required when another user opens the crafted visualization.


23) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-72674)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the Kibana Playground for the RAG feature when processing a user-supplied list of document fields. A remote user can send a crafted request to cause a denial of service.

A single request can cause Kibana to assemble a response far larger than the underlying data, resulting in processing and memory pressure that exhausts instance resources.


24) Missing Authorization (CVE-ID: CVE-2026-72681)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in Kibana Agent Builder when creating and running a tool that invokes a separate Kibana feature's functionality. A remote user can create and run a tool that invokes that functionality to disclose sensitive information.

The issue can also result in privilege escalation.


25) Incorrect authorization (CVE-ID: CVE-2026-72643)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and modify or remove private agents.

The vulnerability exists due to incorrect authorization in Kibana Agent Builder when determining ownership of private agents across multiple authentication realms. A remote user can use the same username in a different authentication realm to disclose sensitive information and modify or remove private agents.

Only configurations that use multiple authentication realms where the user has control over their selected username are vulnerable.


26) Improper privilege management (CVE-ID: CVE-2026-72631)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper privilege management in Kibana Fleet when issuing Elasticsearch API keys for Elastic Agents enrolled in an affected agent policy. A remote user can declare extra data streams in an integration policy to escalate privileges.

The resulting API key allows insertion of new documents and extension of index mappings for specific indices, but does not allow reading, updating, or deleting existing documents.


27) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-72680)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify another user's conversation data.

The vulnerability exists due to authorization bypass through user-controlled key in the Kibana Agent Builder A2A JSON-RPC API endpoint when deriving a stored conversation identifier from user-supplied input. A remote user can supply an identifier already in use by another user to modify another user's conversation data.

Only conversations created through the agent-to-agent interface are affected, and exploitation requires knowledge of or prior sharing of the target conversation identifier within the same space.


28) Incorrect authorization (CVE-ID: CVE-2026-72672)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to incorrect authorization in the Elastic Security field value suggestion capability when querying existing field values while authoring endpoint policy artifacts. A remote user can retrieve field values from Elastic Defend event data to disclose sensitive information.

The issue occurs because Kibana uses its internal Elasticsearch account for these queries and does not verify the caller's Elasticsearch index privileges.


Remediation

Install update from vendor's website.

References