Authorization bypass through user-controlled key in Kibana - CVE-2026-72680
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to modify another user's conversation data.
The vulnerability exists due to authorization bypass through user-controlled key in the Kibana Agent Builder A2A JSON-RPC API endpoint when deriving a stored conversation identifier from user-supplied input. A remote user can supply an identifier already in use by another user to modify another user's conversation data.
Only conversations created through the agent-to-agent interface are affected, and exploitation requires knowledge of or prior sharing of the target conversation identifier within the same space.