Missing Authorization in Kibana - CVE-2026-72664

 

Missing Authorization in Kibana - CVE-2026-72664

Published: August 13, 2026


Vulnerability identifier: #VU142343
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72664
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute unauthorized endpoint response actions on managed hosts.

The vulnerability exists due to missing authorization in Kibana Elastic Security detection rule response actions when associating automated endpoint response actions with a detection rule. A remote user can create a detection rule with automated endpoint response actions to execute unauthorized endpoint response actions on managed hosts.

Exploitation requires deployments that use the Elastic Security solution with Elastic Defend agents enrolled, and the issue is triggered when the rule generates alerts.


Affected software

Kibana

How to mitigate CVE-2026-72664

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.5

External References

Related Security Bulletins