AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72664

MEDIUM · CVSS 6.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Kibana is vulnerable due to a missing authorization flaw that allows users with only detection rule authoring privileges to execute unauthorized endpoint response actions on managed hosts. This can lead to significant security risks, as users may trigger actions like host isolation or process operations without the necessary permissions. Organizations using Kibana for Elastic Security should prioritize addressing this vulnerability to prevent potential misuse of automated response capabilities.

CVE
CVE-2026-72664
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%

Original NVD Description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.