CVE-2026-72665Patch(elastic / kibana)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch elastic kibana systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kibana

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
kibana

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-16: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-16: 108-16
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - Kibana missing authorization allows unprivileged host response actions (CVE-2026-72665) A user who can author/evaluate Elastic Security detection rules can trigger Osquery live queries and Elastic Defend response actions on enrolled agents without the required privileges — host data disclosure or unauthorized state changes. Only affects deployments running Elastic Security with Osquery Manager or Elastic Defend 👉Affected: Kibana 8.5.0–8.19.19, 9.0.0–9.4.4 | Upgrade to 8.19.20 or 9.4.5

    Post summary

    Kibana’s missing authorization flaw (CVE‑2026‑72665) enables unprivileged users to trigger host response actions; upgrading to 8.19.20 or 9.4.5 addresses the issue.

    0000095
    292 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelastickibana---

Explore more