Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana - CVE-2026-72655

 

Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana - CVE-2026-72655

Published: August 13, 2026


Vulnerability identifier: #VU142350
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72655
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify case data without authorization.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the case management API of Elastic Security in Kibana when handling user-controlled object attributes. A remote user can manipulate user-controlled variables to modify case data without authorization.

The issue arises because object attributes accepted by the API were not subject to the same authorization enforcement applied in the user interface.


Affected software

Kibana

How to mitigate CVE-2026-72655

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.5

External References

Related Security Bulletins