CVE-2026-72672
Received Received - Intake

Elasticsearch Field Suggestion Disclosure in Kibana

Vulnerability report for CVE-2026-72672, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Elastic

Description

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
elastic security *
elastic kibana *
elastic elasticsearch *
elastic kibana to 9.4.4 (inc)
elastic kibana 9.4.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-72672 is a security flaw in Kibana versions 9.1.0 through 9.4.4 where the system queries Elastic Defend event data using Kibana's internal Elasticsearch account instead of the user's account. This bypasses proper access controls, allowing authenticated users with Elastic Security privileges but no direct read access to sensitive data to retrieve it.

Detection Guidance

Check Kibana version with command: curl -XGET 'http://localhost:5601/api/console/api_server?path=info&method=GET'. If version is between 9.1.0 and 9.4.4, the system is vulnerable.

Impact Analysis

This vulnerability could allow an attacker with limited privileges to access sensitive data such as process command line arguments, which may contain tokens, credentials, or connection strings from protected hosts. This could lead to unauthorized data exposure or further exploitation.

Compliance Impact

This vulnerability could result in unauthorized access to sensitive data, potentially violating compliance requirements under GDPR, HIPAA, or other regulations that mandate strict access controls and data protection measures.

Mitigation Strategies

Upgrade Kibana to version 9.4.5 or later immediately. No workarounds exist for versions below 9.4.5.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72672. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart