Incorrect authorization in Kibana - CVE-2026-72643

 

Incorrect authorization in Kibana - CVE-2026-72643

Published: August 13, 2026


Vulnerability identifier: #VU142337
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72643
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify or remove private agents.

The vulnerability exists due to incorrect authorization in Kibana Agent Builder when determining ownership of private agents across multiple authentication realms. A remote user can use the same username in a different authentication realm to disclose sensitive information and modify or remove private agents.

Only configurations that use multiple authentication realms where the user has control over their selected username are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-72643

Install security update from vendor's website.

Kibana - addressed in versions 9.4.5, 9.5.1

External References

Related Security Bulletins