PT-2026-71790 · Elastic · Kibana

CVE-2026-72680

·

Published

2026-08-13

·

Updated

2026-08-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description The Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from user-supplied input. The ownership check for this identifier fails to distinguish between a non-existent conversation and one that belongs to another user. Consequently, an authenticated user with Agent Builder read privileges can provide an identifier used by another user in the same space, causing that conversation to be replaced and reassigned to the attacker's account. This results in the original owner permanently losing access to the conversation and its history, impacting the integrity and availability of the data, although the attacker cannot read the overwritten content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-72680
BIT-KIBANA-2026-72680
CVE-2026-72680

Affected Products

Kibana