Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana - CVE-2026-72655
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to modify case data without authorization.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the case management API of Elastic Security in Kibana when handling user-controlled object attributes. A remote user can manipulate user-controlled variables to modify case data without authorization.
The issue arises because object attributes accepted by the API were not subject to the same authorization enforcement applied in the user interface.