
🚨High - Kibana missing authorization allows unprivileged host response actions (CVE-2026-72665) A user who can author/evaluate Elastic Security detection rules can trigger Osquery live queries and Elastic Defend response actions on enrolled agents without the required privileges — host data disclosure or unauthorized state changes. Only affects deployments running Elastic Security with Osquery Manager or Elastic Defend 👉Affected: Kibana 8.5.0–8.19.19, 9.0.0–9.4.4 | Upgrade to 8.19.20 or 9.4.5
Post summary
Kibana’s missing authorization flaw (CVE‑2026‑72665) enables unprivileged users to trigger host response actions; upgrading to 8.19.20 or 9.4.5 addresses the issue.
