CVE-2026-72664: Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72664?
The severity of CVE-2026-72664 is medium, with a CVSS score of 6.5.
What is the risk associated with CVE-2026-72664?
CVE-2026-72664 has an associated risk score of 38, indicating a medium level of risk.
How do I fix CVE-2026-72664?
To fix CVE-2026-72664, ensure proper authorization controls are implemented in Kibana to restrict access to Elastic Defend response actions.
What type of vulnerability is CVE-2026-72664?
CVE-2026-72664 is classified as a Missing Authorization vulnerability (CWE-862).
What can exploit CVE-2026-72664?
CVE-2026-72664 can be exploited by a Kibana user with detection rule authoring privileges, allowing unauthorized execution of response actions.