PT-2026-71782 · Elastic · Kibana
CVE-2026-72672
·
Published
2026-08-13
·
Updated
2026-08-19
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kibana (affected versions not specified)
Description
A flaw in the Elastic Security capability for suggesting field values during the authoring of endpoint policy artifacts allows an authenticated user to bypass index privilege checks. The system queries Elastic Defend event data using Kibana's internal Elasticsearch account rather than the account of the requesting user. Consequently, a user with Elastic Security feature privileges but without read access to Elastic Defend event indices can retrieve sensitive field values, such as process command line arguments, which may contain tokens, credentials, and connection strings.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kibana