Description
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its user-facing equivalents require, and it retrieved data with elevated internal permissions rather than the permissions of the requesting user. As a result, an authenticated low-privileged Kibana user with no Security Solution privileges, endpoint privileges and no Elasticsearch privileges on the underlying data, could read endpoint response action records and the corresponding response content returned by managed hosts.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing Authorization (CWE-862) in an internal Kibana data retrieval capability allows an authenticated low‑privileged user to read endpoint response action records and the content returned by managed hosts. The vulnerability arises because the functionality does not enforce the same Security Solution and endpoint privileges that its user‑facing counterparts do, effectively elevating the privileges of the internal request. This can lead to a confidentiality compromise where sensitive host response data is exposed to unauthorized users.

Affected Systems

Kibana from Elastic is affected. The vulnerability exists in deployments that utilize the Elastic Defend endpoint response actions, and the specific version impact is not listed, so all current Kibana releases should be considered potentially vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that known exploitation is unlikely but cannot be ruled out. Local authentication is required to exploit the flaw, meaning a low‑privileged user account that has access to Kibana can trigger the disclosure. The official reference points to a security update that mitigates the issue, implying that the vulnerability is actively tracked by Elastic.

Generated by OpenCVE AI on August 13, 2026 at 21:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana security update that addresses the missing authorization flaw.
  • Review and tighten role definitions so that only users with the appropriate Security Solution and endpoint privileges can access the internal endpoint response action functionality.
  • Disable or restrict the Elastic Defend integration if the update cannot be applied immediately, thereby preventing the exposed data path from being reachable.

Generated by OpenCVE AI on August 13, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its user-facing equivalents require, and it retrieved data with elevated internal permissions rather than the permissions of the requesting user. As a result, an authenticated low-privileged Kibana user with no Security Solution privileges, endpoint privileges and no Elasticsearch privileges on the underlying data, could read endpoint response action records and the corresponding response content returned by managed hosts.
Title Missing Authorization in Kibana Leading to Information Disclosure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:30:47.621Z

Reserved: 2026-08-10T11:17:45.102Z

Link: CVE-2026-72661

cve-icon Vulnrichment

Updated: 2026-08-13T20:30:43.978Z

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:26.453

Modified: 2026-08-13T21:18:10.980

Link: CVE-2026-72661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses