Description
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing Authorization (CWE-862) in Kibana allows a user who can author detection rules to attach and trigger automated endpoint response actions without having the dedicated privileges that normally control those actions. The vulnerability enables the execution of commands such as host isolation, process termination, and arbitrary process execution on managed hosts whenever the associated detection rule generates an alert. Consequently, an attacker with only rule‑authoring rights can covertly cause damage or disrupt services on endpoints by leveraging the endpoint response feature.

Affected Systems

The issue applies to installations of Elastic Kibana that include the Elastic Security module. No specific product versions are listed, so all deployed Kibana instances with the security solution enabled are potentially affected until a corrected release is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS score is currently not available, while the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via Kibana’s web interface, accessible to users with rule‑authoring privileges; it can be exploited by an insider or a compromised privileged account. Because the vulnerability directly bypasses endpoint privilege checks, it carries a moderate risk of confidentiality, integrity, and availability compromise, especially in environments where detection rule authors exist without corresponding endpoint privileges.

Generated by OpenCVE AI on August 13, 2026 at 21:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to a version that includes the documented fix for the missing authorization issue
  • Review and remove endpoint response action privileges from users who only require detection‑rule authoring rights
  • Enforce least‑privilege access controls by separating rule‑authoring and endpoint‑action roles
  • Monitor Kibana logs for anomalous rule creation or execution of endpoint actions
  • Verify that updated roles adhere to the principle of least privilege in the security strategy

Generated by OpenCVE AI on August 13, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.
Title Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-14T16:38:42.016Z

Reserved: 2026-08-10T11:17:45.103Z

Link: CVE-2026-72664

cve-icon Vulnrichment

Updated: 2026-08-14T16:38:36.755Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:26.910

Modified: 2026-08-28T15:32:26.217

Link: CVE-2026-72664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses