Description
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when the Kibana Agent Builder does not validate the requesting user's permissions against those required by a separate Kibana feature before creating and executing a tool that utilizes that feature. This omission allows an attacker who can invoke the Agent Builder to execute privileged operations and gain access to data that the user is not authorized to read.

Affected Systems

Elastic’s Kibana product is affected. No specific version range is provided in the advisory, so all deployed instances should be investigated until a patch becomes available.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain, though the design flaw could be exploited by users who can interact with the Agent Builder. The attack likely requires authenticated access to Kibana, and the impact spans both privilege escalation and unauthorized data disclosure.

Generated by OpenCVE AI on August 13, 2026 at 21:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana patch released by Elastic that addresses the Agent Builder privilege check.
  • Restrict or disable Agent Builder functionality for user accounts that do not require it, ensuring that only authorized roles can invoke it.
  • Conduct an audit of current Kibana roles to confirm that users lack permissions tied to the vulnerable feature and adjust roles accordingly.
  • Monitor Kibana logs for unexpected Agent Builder usage to detect possible exploitation attempts.

Generated by OpenCVE AI on August 13, 2026 at 21:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Thu, 13 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.
Title Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-14T03:56:10.063Z

Reserved: 2026-08-10T11:17:58.730Z

Link: CVE-2026-72681

cve-icon Vulnrichment

Updated: 2026-08-13T20:33:39.854Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-13T20:17:28.853

Modified: 2026-09-03T18:59:33.933

Link: CVE-2026-72681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses