Missing Authorization in Kibana - CVE-2026-72681
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in Kibana Agent Builder when creating and running a tool that invokes a separate Kibana feature's functionality. A remote user can create and run a tool that invokes that functionality to disclose sensitive information.
The issue can also result in privilege escalation.