PatchSiren cyber security CVE debrief
CVE-2026-72672 Elastic CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:27.777Z and has not been modified since then. The NVD entry is currently Analyzed. The Elastic Security capability suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts. This could potentially allow unauthorized access to sensitive information.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-04
Who should care
Elastic Kibana administrators, security teams, and users with access to Elastic Security features should be aware of this vulnerability. They should review their current privileges and access controls to ensure that they are not inadvertently exposing sensitive data. Additionally, they should monitor Elastic Defend event indices for unauthorized access and apply vendor-provided patches or updates as soon as possible. Users with limited privileges could access sensitive data, including process command line arguments, from Elastic Defend event indices, which could lead to further exploitation.
Technical summary
The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.
Defensive priority
Authenticated users with limited privileges could access sensitive data, including process command line arguments, from Elastic Defend event indices.
Recommended defensive actions
- Inventory Elastic Kibana instances to identify potential exposure.
- Verify user privileges and access controls for Elastic Security features.
- Monitor Elastic Defend event indices for unauthorized access.
- Apply vendor-provided patches or updates.
- Restrict access to sensitive data in Elastic Defend event indices.
Evidence notes
The Elastic Security capability suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72672 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72672
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72672 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72672
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-9-4-5-security-update-esa-2026-89/389536
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.