Missing Authorization in Kibana - CVE-2026-72661
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in an internal Kibana data retrieval capability used by Elastic Defend endpoint response actions when handling data retrieval requests. A remote user can access functionality not properly constrained by ACLs to disclose sensitive information.
The issue affects data retrieval performed with elevated internal permissions rather than the permissions of the requesting user, allowing access to endpoint response action records and corresponding response content returned by managed hosts.