Incorrect authorization in Kibana - CVE-2026-72630

 

Incorrect authorization in Kibana - CVE-2026-72630

Published: August 13, 2026


Vulnerability identifier: #VU142354
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72630
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in Kibana Fleet when updating an existing integration policy. A remote user can replace the integration referenced by a stored policy and supply that integration's configuration to escalate privileges.

Exploitation requires an authenticated user with only the Elastic Defend endpoint policy management privilege.


Affected software

Kibana

How to mitigate CVE-2026-72630

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.5, 9.5.1

External References

Related Security Bulletins