Missing Authorization in Kibana - CVE-2026-72664
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to execute unauthorized endpoint response actions on managed hosts.
The vulnerability exists due to missing authorization in Kibana Elastic Security detection rule response actions when associating automated endpoint response actions with a detection rule. A remote user can create a detection rule with automated endpoint response actions to execute unauthorized endpoint response actions on managed hosts.
Exploitation requires deployments that use the Elastic Security solution with Elastic Defend agents enrolled, and the issue is triggered when the rule generates alerts.