Improper privilege management in Kibana - CVE-2026-72631

 

Improper privilege management in Kibana - CVE-2026-72631

Published: August 13, 2026


Vulnerability identifier: #VU142336
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72631
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper privilege management in Kibana Fleet when issuing Elasticsearch API keys for Elastic Agents enrolled in an affected agent policy. A remote user can declare extra data streams in an integration policy to escalate privileges.

The resulting API key allows insertion of new documents and extension of index mappings for specific indices, but does not allow reading, updating, or deleting existing documents.


Affected software

Kibana

How to mitigate CVE-2026-72631

Install security update from vendor's website.

Kibana - addressed in versions 9.4.5, 9.5.1

External References

Related Security Bulletins