PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72672 Elastic CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:27.777Z and has not been modified since then. The NVD entry is currently Analyzed. The Elastic Security capability suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts. This could potentially allow unauthorized access to sensitive information.

Vendor
Elastic
Product
Kibana
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-04
Advisory published
2026-08-13
Advisory updated
2026-09-04

Who should care

Elastic Kibana administrators, security teams, and users with access to Elastic Security features should be aware of this vulnerability. They should review their current privileges and access controls to ensure that they are not inadvertently exposing sensitive data. Additionally, they should monitor Elastic Defend event indices for unauthorized access and apply vendor-provided patches or updates as soon as possible. Users with limited privileges could access sensitive data, including process command line arguments, from Elastic Defend event indices, which could lead to further exploitation.

Technical summary

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.

Defensive priority

Authenticated users with limited privileges could access sensitive data, including process command line arguments, from Elastic Defend event indices.

Recommended defensive actions

  • Inventory Elastic Kibana instances to identify potential exposure.
  • Verify user privileges and access controls for Elastic Security features.
  • Monitor Elastic Defend event indices for unauthorized access.
  • Apply vendor-provided patches or updates.
  • Restrict access to sensitive data in Elastic Defend event indices.

Evidence notes

The Elastic Security capability suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72672 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72672

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72672 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72672

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.