Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery live queries in one space can have a query carried out on hosts belonging to another space, resulting in disclosure of information from those hosts to the Osquery results data stream.
Published: 2026-08-13
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization bypass that allows a user who can run Osquery live queries in one Kibana space to trigger a query on Elastic Agents assigned to a different space. The attacker can request a query using a user-controlled key, which is not properly constrained by ACLs. The executed query returns host data to the Osquery results stream, resulting in disclosure of sensitive information. The weakness is classified as CWE‑639, a typical privilege escalation flaw that can be exploited by an authenticated user.

Affected Systems

This flaw affects Elastic Kibana installations. Any deployment where users have permissions to run Osquery live queries in a space and where agents are assigned to other spaces is potentially vulnerable. The data provided does not identify a specific version, so all deployed instances are considered at risk until the official fix is applied.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with query privileges in one space and the ability to craft an OS query key. No additional system compromise is required to achieve the data disclosure.

Generated by OpenCVE AI on August 13, 2026 at 21:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Kibana to the latest version that includes the authorized query bypass fix.
  • Audit and tighten space‑level ACLs so that only users assigned to a space can submit queries affecting that space.
  • Disable or restrict the ability to submit Osquery live queries across spaces until the security update is applied.

Generated by OpenCVE AI on August 13, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery live queries in one space can have a query carried out on hosts belonging to another space, resulting in disclosure of information from those hosts to the Osquery results data stream.
Title Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-14T16:37:39.896Z

Reserved: 2026-08-10T11:17:45.103Z

Link: CVE-2026-72666

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:27.157

Modified: 2026-08-28T15:32:26.217

Link: CVE-2026-72666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key