CVE-2026-72661
Last modified
CVE-2026-72661 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its user-facing equivalents require, and it retrieved data with elevated internal permissions rather than the permissions of the requesting user. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its user-facing equivalents require, and it retrieved data with elevated internal permissions rather than the permissions of the requesting user. As a result, an authenticated low-privileged Kibana user with no Security Solution privileges, endpoint privileges and no Elasticsearch privileges on the underlying data, could read endpoint response action records and the corresponding response content returned by managed hosts.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 8.12.0, < 8.19.19 |
| Elastic | Kibana | >= 9.0.0, < 9.3.8 |
| Elastic | Kibana | >= 9.4.0, < 9.4.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-72661?
How severe is CVE-2026-72661?
How do I fix CVE-2026-72661?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72656Memory Allocation with Excessive Size Value (CWE-789) in the…6.5
- CVE-2026-72657Authorization Bypass Through User-Controlled Key (CWE-639) i…6.5
- CVE-2026-72658Cross-Site Request Forgery (CWE-352) in Kibana can lead to p…7.3
- CVE-2026-72659Allocation of Resources Without Limits or Throttling (CWE-77…6.5
- CVE-2026-7266A vulnerability was detected in SourceCodester Pizzafy Ecomm…6.3
- CVE-2026-72660Uncaught Exception (CWE-248), resulting from Improper Input …6.5
- CVE-2026-72663Inefficient Algorithmic Complexity (CWE-407) in Kibana can l…6.5
- CVE-2026-72664Missing Authorization (CWE-862) in Kibana can lead to unauth…6.5
- CVE-2026-72665Missing Authorization (CWE-862) in Kibana can lead to unauth…8.1
- CVE-2026-72666Authorization Bypass Through User-Controlled Key (CWE-639) i…6.8
- CVE-2026-72667Allocation of Resources Without Limits or Throttling (CWE-77…6.5
- CVE-2026-72669The state that Kibana stores for an Observability Onboarding…7.6
Are you affected by CVE-2026-72661?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
