Description
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.
Published: 2026-08-13
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw (CWE-862) in Kibana that allows a user with permission to author and evaluate Elastic Security detection rules to trigger Osquery and Elastic Defend response actions on enrolled hosts without possessing the normally required Osquery live query or Elastic Defend privileges. The unauthorized execution can disclose host information or cause unauthorized changes to host state.

Affected Systems

Elastic Kibana is affected. Specific product versions are not listed in the available data, so all deployed instances of Kibana should be reviewed for exposure. The absence of version details requires administrators to verify whether their installations fall within the scope of this flaw.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity. EPSS is not available and the flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploit yet. The likely attack path involves the Kibana web interface and requires a user with rule authoring and evaluation rights, which the vendor had incorrectly assumed were sufficient to enforce all ACLs. Once a malicious or compromised rule is created, response actions can be executed against hosts, bypassing normal privilege checks.

Generated by OpenCVE AI on August 13, 2026 at 21:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana security update provided by Elastic to enforce correct access control checks for host response actions.
  • Restrict user permissions to rule authoring and evaluation to only those who truly need those capabilities, and review existing rule‑creation privileges.
  • Verify that all controlled hosts have the latest Elastic Defend and Osquery agents installed and that agent settings enforce ACL restrictions on response action execution.

Generated by OpenCVE AI on August 13, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.
Title Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-14T16:38:11.929Z

Reserved: 2026-08-10T11:17:45.103Z

Link: CVE-2026-72665

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:27.033

Modified: 2026-08-28T15:32:26.217

Link: CVE-2026-72665

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses