Threats Tagged 'bit-elk-2026-72655'
View all threats tagged with 'bit-elk-2026-72655'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bit-elk-2026-72655'
Click on any threat for detailed analysis and mitigation recommendations
Elk: Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data Modification (CVE-2026-72655)CVE-2026-72655 0 A vulnerability in Kibana's Elastic Security case management allows authenticated users without case editing privileges to modify case data. This occurs because the case management API does not enforce the same authorization checks as the user interface, enabling low-privileged users to alter case records they should only view. The issue affects versions 8.0.0 up to but not including 8.19.20, and 9.0.0 up to but not including 9.4.5. A patch is available to address this improper authorization enforcement. Join the discussion | GCVE Database | 08/19/2026, 08:40:27 UTC Added: 08/19/2026, 13:50:34 UTC |
CVE-2026-72655: CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Elastic KibanaCVE-2026-72655 0 Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges, via Manipulating User-Controlled Variables (CAPEC-77). Object attributes accepted by the case management API were not subject to the same authorization enforcement applied in the user interface, so a low-privileged user could alter case records they were only entitled to view. Join the discussion | CVE Database V5 | 08/19/2026, 08:40:27 UTC Added: 08/13/2026, 19:26:58 UTC |
Showing 1 to 2 of 2 results