Improper privilege management in Kibana - CVE-2026-72631
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in Kibana Fleet when issuing Elasticsearch API keys for Elastic Agents enrolled in an affected agent policy. A remote user can declare extra data streams in an integration policy to escalate privileges.
The resulting API key allows insertion of new documents and extension of index mappings for specific indices, but does not allow reading, updating, or deleting existing documents.