Missing Authorization in Kibana - CVE-2026-72665
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information or modify host state.
The vulnerability exists due to missing authorization in Elastic Security detection rules and response action functionality when authoring and evaluating detection rules. A remote user can trigger Osquery or Elastic Defend response actions on enrolled agents to disclose sensitive information or modify host state.
Only deployments using the Elastic Security solution together with Osquery Manager or Elastic Defend are affected. Host-side impact requires enrolled agents.