PatchSiren cyber security CVE debrief
CVE-2026-72665 Elastic CVE debrief
The CVE-2026-72665 vulnerability in Kibana allows a user with the ability to author and evaluate Elastic Security detection rules to execute Osquery and Elastic Defend response actions on managed hosts without the required privileges. This can lead to unauthorized disclosure of information or changes to the state of affected hosts. Elastic Kibana users, administrators, and security teams should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-08-13T20:17:27.033Z and has not been modified since then. Affected product deployments should be identified and owners assigned for follow-up.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-02
Who should care
Elastic Kibana users, administrators, and security teams should be aware of this vulnerability and take necessary actions to mitigate it. Affected operators, platforms, and vulnerability-management teams need to review their Kibana deployments and ensure they are running versions 8.19.20 or later, or 9.4.5 or later. Security teams should monitor for suspicious activity related to Osquery and Elastic Defend response actions. Asset inventory and change management processes should be updated to account for this vulnerability. Compensating controls, such as restricting access to Elastic Security detection rules, should be implemented while remediation is scheduled and verified. Source tracking and monitoring should be used to detect potential exploitation attempts. Rollback/change windows should be planned to ensure timely remediation of affected systems. Vendor patch guidance should be followed to apply necessary updates. Exposure review should be conducted to identify potential vulnerabilities in Kibana deployments. Monitoring and detection capabilities should be reviewed to ensure they can detect potential exploitation attempts. Asset inventory and change management processes should be updated to account for this vulnerability. Compensating controls, such as restricting access to Elastic Security detection rules, should be implemented while remediation is scheduled and verified. Source tracking and monitoring should be used to detect potential exploitation attempts. Rollback/change windows should be planned to ensure timely remediation of affected systems. Vendor patch guidance should be followed to apply necessary updates. Exposure review should be conducted to identify potential vulnerabilities in Kibana deployments. Monitoring and detection capabilities should be reviewed to ensure they can detect potential exploitation attempts. Asset inventory and change management processes should be updated to account for this vulnerability. Compensating controls, such as restricting access to Elastic Security detection rules, should be implemented while remediation is scheduled and verified. Source tracking and monitoring should be used to detect potential exploitation. 7
Technical summary
The CVE-2026-72665 vulnerability in Kibana allows a user with the ability to author and evaluate Elastic Security detection rules to execute Osquery and Elastic Defend response actions on managed hosts without the required privileges. This can lead to unauthorized disclosure of information or changes to the state of affected hosts. The vulnerability is classified as a Missing Authorization (CWE-862) issue. A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities.
Defensive priority
Elastic Kibana users should verify their Kibana versions and ensure they are running versions 8.19.20 or later, or 9.4.5 or later, as these versions include patches for the vulnerability.
Recommended defensive actions
- Verify Kibana version and upgrade to 8.19.20 or later, or 9.4.5 or later.
- Restrict access to Elastic Security detection rules to authorized users.
- Monitor for suspicious activity related to Osquery and Elastic Defend response actions.
- Conduct an exposure review to identify potential vulnerabilities in Kibana deployments.
- Implement compensating controls, such as restricting access to Elastic Security detection rules, while remediation is scheduled and verified.
- Plan rollback/change windows to ensure timely remediation of affected systems.
- Use source tracking and monitoring to detect potential exploitation attempts.
Evidence notes
The CVE-2026-72665 record indicates a Missing Authorization vulnerability in Kibana, which can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts. A Kibana user who can author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the necessary privileges.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72665 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72665
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72665 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72665
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-96/389528
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.