PatchSiren cyber security CVE debrief
CVE-2026-72630 Elastic CVE debrief
The CVE-2026-72630 record describes an Incorrect Authorization vulnerability in Kibana Fleet, which can lead to privilege escalation via Privilege Abuse. This issue allows an authenticated user with the Elastic Defend endpoint policy management privilege to update an existing integration policy by providing a replacement integration, potentially leading to unauthorized access. Users and administrators of Kibana Fleet should be aware of this vulnerability and take necessary precautions. The CVE record was published on 2026-08-13T20:17:23.813Z and has not been modified since then. To address this vulnerability, it is crucial to review and restrict integration policy management privileges in Kibana Fleet, monitor and audit user activities related to integration policy updates, and implement additional access controls to prevent unauthorized integration policy modifications.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-08-28
Who should care
Users and administrators of Kibana Fleet, especially those with integration policy management privileges, should be aware of this vulnerability and take necessary precautions to prevent potential privilege escalation attacks. This includes reviewing and restricting integration policy management privileges, monitoring and auditing user activities related to integration policy updates, and implementing additional access controls to prevent unauthorized integration policy modifications. Security teams and platform administrators should also be informed about the potential risks and take steps to mitigate them, such as verifying and updating Kibana Fleet configurations to ensure proper authorization checks are in place and tracking exceptions and retesting remediated assets to close the item only after evidence is documented. Vulnerability management teams should prioritize patching or mitigating this vulnerability to prevent potential security breaches, and asset owners should be notified about the potential risks and take necessary actions to protect their assets. Monitoring and detection teams should also be aware of the potential indicators of compromise and review relevant logs for exposed assets that need extra review. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified, and source tracking should be implemented to monitor for potential security breaches. Rollback and change window management teams should also be informed about the potential risks and take necessary actions to prevent unauthorized changes. Overall, a coordinated effort from various stakeholders is necessary to effectively mitigate this vulnerability and prevent potential security breaches. Operational security teams should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. They should also check relevant monitoring, detection, and logs for exposed assets that need extra review, and track exceptions, retest remediated assets, and close the item only after evidence is is 0
Technical summary
The vulnerability exists in Kibana Fleet, where an authenticated user with the Elastic Defend endpoint policy management privilege can update an existing integration policy by providing a replacement integration. This can potentially lead to privilege escalation, as the user may be able to convert an endpoint policy they administer into a policy for a different integration and supply that integration's configuration. The issue arises from the fact that Fleet restricts some callers to managing integration policies for one specific integration, but when an existing integration policy is updated, this restriction is evaluated against the integration recorded on the stored policy rather than against the replacement integration supplied with the update.
Defensive priority
Authenticated users with limited privileges may be able to escalate privileges by manipulating integration policies in Kibana Fleet.
Recommended defensive actions
- Review and restrict integration policy management privileges in Kibana Fleet.
- Monitor and audit user activities related to integration policy updates.
- Implement additional access controls to prevent unauthorized integration policy modifications.
- Verify and update Kibana Fleet configurations to ensure proper authorization checks are in place.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record indicates an Incorrect Authorization vulnerability in Kibana Fleet, which could lead to privilege escalation. An authenticated user with the Elastic Defend endpoint policy management privilege may be able to convert an endpoint policy they administer into a policy for a different integration and supply that integration's configuration.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72630 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72630
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72630 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72630
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-20-9-4-5-9-5-1-security-update-esa-2026-127/389531
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.