Incorrect authorization in Kibana - CVE-2026-72643
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify or remove private agents.
The vulnerability exists due to incorrect authorization in Kibana Agent Builder when determining ownership of private agents across multiple authentication realms. A remote user can use the same username in a different authentication realm to disclose sensitive information and modify or remove private agents.
Only configurations that use multiple authentication realms where the user has control over their selected username are vulnerable.