CVE-2026-72680
Received Received - Intake

Kibana Agent Builder A2A conversation ownership manipulation

Vulnerability report for CVE-2026-72680, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Elastic

Description

Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. As a result, an authenticated user holding only the Agent Builder read privilege can supply an identifier already in use by another user in the same space and cause that user's conversation to be replaced and reassigned to the requesting account. The original owner permanently loses access to the conversation and its history. The impact is limited to loss of integrity and availability of the affected conversation; the attacker does not read the overwritten content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
elastic kibana_agent_builder *
elastic kibana From 9.2.0 (inc) to 9.4.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Kibana Agent Builder allows an authenticated user with read privileges to manipulate a user-controlled key to bypass authorization. The attacker can replace and reassign another user's conversation to their own account, causing the original owner to lose access to the conversation and its history. The impact is limited to loss of integrity and availability of the affected conversation, as the attacker cannot read the overwritten content.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized data modification where your conversations are replaced and reassigned to another user. You would permanently lose access to your conversation and its history, affecting the integrity and availability of your stored data.

Mitigation Strategies

Upgrade Kibana to version 9.4.5 or later to resolve the vulnerability. If upgrading is not possible, disable Agent Builder globally via configuration or disable the feature in all Kibana spaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72680. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart