CVE-2026-72681

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 20:17

Updated : 2026-09-03 18:59


NVD link : CVE-2026-72681

Mitre link : CVE-2026-72681

CVE.ORG link : CVE-2026-72681


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-862

Missing Authorization