CVE-2026-72664
Received Received - Intake

Missing Authorization in Kibana Allows Unauthorized Response Actions

Vulnerability report for CVE-2026-72664, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Elastic

Description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
elastic kibana *
elastic kibana From 8.9.0 (inc) to 8.19.20 (exc)
elastic kibana From 9.0.0 (inc) to 9.4.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-72664 is a missing authorization flaw in Kibana versions 8.19.20 and 9.4.5 or earlier. It allows users with only detection rule authoring privileges to execute unauthorized endpoint response actions on managed hosts without proper privileges for host isolation, process operations, or execute operations. When a detection rule triggers alerts, these unauthorized actions are carried out against matching hosts.

Detection Guidance

Check Kibana versions for affected releases (8.9.0 to 8.19.19, 9.0.0 to 9.4.4). Review detection rule configurations for unauthorized response actions. Inspect Elastic Defend agent logs for unexpected host isolation or process operations.

Impact Analysis

This vulnerability could allow an attacker with limited privileges to perform unauthorized actions on managed hosts, such as isolating hosts, manipulating processes, or executing commands. This may lead to data breaches, system compromise, or disruption of services if response actions are triggered by detection rules.

Compliance Impact

This vulnerability could lead to unauthorized access or actions on sensitive data, potentially violating compliance requirements under GDPR, HIPAA, or other regulations. Unauthorized endpoint actions may result in data exposure, unauthorized modifications, or lack of audit trails, increasing regulatory risk.

Mitigation Strategies

Upgrade Kibana to versions 8.19.20 or 9.4.5 immediately. Ensure users have only required privileges. Monitor for unauthorized response actions in detection rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72664. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart