Incorrect authorization in Kibana - CVE-2026-72630
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in Kibana Fleet when updating an existing integration policy. A remote user can replace the integration referenced by a stored policy and supply that integration's configuration to escalate privileges.
Exploitation requires an authenticated user with only the Elastic Defend endpoint policy management privilege.