Description
The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.
Published: 2026-08-13
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because Kibana executes Elastic Security policy queries against Elasticsearch using an internal account rather than the credentials of the requesting user. Only the Kibana feature privilege is verified, while the caller’s Elasticsearch index privileges are ignored. An authenticated user who possesses Elastic Security feature rights but lacks read access to the Elastic Defend event indices can therefore retrieve field values from those indices, including process command line arguments that often contain tokens, credentials, and connection strings. This flaw is documented as CWE-863 and can lead to sensitive information leakage.

Affected Systems

Elastic Kibana when the Elastic Security feature is enabled. No specific version numbers are provided, so the issue applies to all affected releases until patched.

Risk and Exploitability

The CVSS score of 7.7 reflects a moderate to high severity for information leakage. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker must be authenticated and granted the Elastic Security feature privilege; the attack can be performed via the Kibana UI or API without requiring index‑level read permissions. While the attack vector requires internal access, the potential impact on confidential operational data is high. No public exploitation examples are known at this time.

Generated by OpenCVE AI on August 13, 2026 at 22:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Elastic Security / Kibana update that includes the privilege validation fix.
  • Restrict the Elastic Security feature privilege to only users who truly need it, removing it from all other roles.
  • Revoke or restrict read permissions on Elastic Defend event indices for users that do not require them, ensuring that index‑level access controls are enforced.

Generated by OpenCVE AI on August 13, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.
Title Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event Data
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:32:52.561Z

Reserved: 2026-08-10T11:17:49.704Z

Link: CVE-2026-72672

cve-icon Vulnrichment

Updated: 2026-08-13T20:32:49.028Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:27.777

Modified: 2026-08-28T15:32:26.217

Link: CVE-2026-72672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:15:03Z

Weaknesses