CVE-2026-72665
Received Received - Intake

Missing Authorization in Kibana Allows Unauthorized Osquery and Elastic Defend Actions

Vulnerability report for CVE-2026-72665, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Elastic

Description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
elastic kibana *
elastic kibana to 8.19.20 (exc)
elastic kibana to 9.4.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-72665 is a missing authorization flaw in Kibana that allows users with permission to create detection rules to execute unauthorized Osquery and Elastic Defend actions on managed hosts without proper privileges. This occurs due to improperly constrained functionality, enabling actions typically restricted by access control lists.

Detection Guidance

To detect this vulnerability, check if your Kibana version is 8.19.19 or earlier (8.x series) or 9.4.4 or earlier (9.x series). If so, the system is vulnerable. Use commands like 'curl -X GET http://<kibana-host>:<port>/api/status' to check the version. Also, review Elastic Security detection rules for unauthorized Osquery or Elastic Defend actions.

Impact Analysis

This vulnerability can lead to information disclosure from affected hosts or unauthorized changes to their state. Attackers could exploit it to run queries or actions on managed systems without the required permissions, potentially compromising data integrity or confidentiality.

Mitigation Strategies

Upgrade Kibana to version 8.19.20 or later (8.x series) or 9.4.5 or later (9.x series) immediately. There are no workarounds for users unable to upgrade. Ensure no unauthorized Osquery or Elastic Defend actions are being executed by reviewing recent detection rule evaluations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72665. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart