CVE-2026-72672: CWE-863 Incorrect Authorization in Elastic Kibana
The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.
AI Analysis
Technical Summary
The vulnerability CVE-2026-72672 in Elastic Kibana 9.1.0 involves incorrect authorization (CWE-863) in the Elastic Security capability that suggests existing field values during endpoint policy artifact authoring. Kibana uses its internal Elasticsearch account to query Elastic Defend event data instead of the caller's account, verifying only Kibana feature privileges and not the caller's Elasticsearch index privileges. Consequently, an authenticated user with Elastic Security feature privileges but lacking read access to Elastic Defend event indices can access sensitive data fields, including process command line arguments containing sensitive operational details.
Potential Impact
An authenticated user with Elastic Security feature privileges but no read access to Elastic Defend event indices can retrieve sensitive information from those indices. This includes process command line arguments that may contain tokens, credentials, connection strings, and other sensitive operational details from protected hosts. The vulnerability does not impact data integrity or availability but results in a confidentiality breach of sensitive operational data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a fix is available, restrict Elastic Security feature privileges to trusted users only and monitor for any unusual access patterns. Follow updates from Elastic for official remediation.
CVE-2026-72672: CWE-863 Incorrect Authorization in Elastic Kibana
Description
The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.
CVSS v3.1
Score 7.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-72672 in Elastic Kibana 9.1.0 involves incorrect authorization (CWE-863) in the Elastic Security capability that suggests existing field values during endpoint policy artifact authoring. Kibana uses its internal Elasticsearch account to query Elastic Defend event data instead of the caller's account, verifying only Kibana feature privileges and not the caller's Elasticsearch index privileges. Consequently, an authenticated user with Elastic Security feature privileges but lacking read access to Elastic Defend event indices can access sensitive data fields, including process command line arguments containing sensitive operational details.
Potential Impact
An authenticated user with Elastic Security feature privileges but no read access to Elastic Defend event indices can retrieve sensitive information from those indices. This includes process command line arguments that may contain tokens, credentials, connection strings, and other sensitive operational details from protected hosts. The vulnerability does not impact data integrity or availability but results in a confidentiality breach of sensitive operational data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a fix is available, restrict Elastic Security feature privileges to trusted users only and monitor for any unusual access patterns. Follow updates from Elastic for official remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- elastic
- Date Reserved
- 2026-08-10T11:17:49.704Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7e1a84bf8831d539b1837c
Added to database: 08/13/2026, 19:27:00 UTC
Last enriched: 08/13/2026, 19:41:24 UTC
Last updated: 08/13/2026, 21:58:35 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.