PT-2026-71752 · Elastic · Kibana Fleet+1

CVE-2026-72630

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana Fleet (affected versions not specified)
Description Incorrect Authorization in Kibana Fleet allows for privilege escalation through privilege abuse. The system restricts certain users to managing integration policies for a single specific integration. However, during the update of an existing integration policy, the restriction is checked against the integration stored in the policy instead of the replacement integration provided in the update. Consequently, an authenticated user with only the Elastic Defend endpoint policy management privilege can convert an endpoint policy they manage into a policy for a different integration and simultaneously provide that integration's configuration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-72630
BIT-KIBANA-2026-72630
CVE-2026-72630

Affected Products

Kibana
Kibana Fleet