CVE-2026-72681: Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-72681?
CVE-2026-72681 is a vulnerability in Elastic Kibana Agent Builder that allows for privilege escalation due to missing authorization.
What is the severity of CVE-2026-72681?
CVE-2026-72681 has a medium severity rating of 6.5 according to the CVSS scoring system.
How do I fix CVE-2026-72681?
To fix CVE-2026-72681, ensure you update to the latest version of Elastic Kibana that addresses this vulnerability.
What are the potential impacts of CVE-2026-72681?
CVE-2026-72681 can lead to privilege escalation and potential disclosure of sensitive information.
What is the affected software for CVE-2026-72681?
The affected software for CVE-2026-72681 is Elastic Kibana Agent Builder.