PT-2026-71790 · Elastic · Kibana
CVE-2026-72680
·
Published
2026-08-13
·
Updated
2026-08-19
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kibana (affected versions not specified)
Description
The Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from user-supplied input. The ownership check for this identifier fails to distinguish between a non-existent conversation and one that belongs to another user. Consequently, an authenticated user with Agent Builder read privileges can provide an identifier used by another user in the same space, causing that conversation to be replaced and reassigned to the attacker's account. This results in the original owner permanently losing access to the conversation and its history, impacting the integrity and availability of the data, although the attacker cannot read the overwritten content.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kibana