PT-2026-71777 · Elastic · Kibana

CVE-2026-72666

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description An authorization bypass exists where a user can execute unauthorized queries against Elastic Agents assigned to a Kibana space they are not permitted to access. This occurs because functionality is not properly constrained by Access Control Lists (ACLs), which are security mechanisms used to define permissions for users or systems. A user authorized to perform Osquery live queries in one space can trigger queries on hosts in another space, leading to the disclosure of information from those hosts via the Osquery results data stream.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-72666
BIT-KIBANA-2026-72666
CVE-2026-72666

Affected Products

Kibana