AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72681

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Kibana Agent Builder is vulnerable due to improper verification of user privileges, potentially allowing unauthorized users to execute features they should not have access to. This flaw could lead to privilege escalation and the disclosure of sensitive information. Organizations using Kibana should prioritize addressing this vulnerability to protect against unauthorized access and data exposure.

CVE
CVE-2026-72681
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.