Missing Authorization in Kibana - CVE-2026-72665

 

Missing Authorization in Kibana - CVE-2026-72665

Published: August 13, 2026


Vulnerability identifier: #VU142342
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72665
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information or modify host state.

The vulnerability exists due to missing authorization in Elastic Security detection rules and response action functionality when authoring and evaluating detection rules. A remote user can trigger Osquery or Elastic Defend response actions on enrolled agents to disclose sensitive information or modify host state.

Only deployments using the Elastic Security solution together with Osquery Manager or Elastic Defend are affected. Host-side impact requires enrolled agents.


Affected software

Kibana

How to mitigate CVE-2026-72665

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.5

External References

Related Security Bulletins