These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An authenticated user with read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and access diagnostic content from agents in other Kibana spaces due to missing authorization in the Kibana Fleet feature. This issue, tracked as CVE-2026-78595, was publicly disclosed on September 3, 2026. The vulnerability allows information disclosure via Privilege Abuse (CAPEC-122). Defender [truncated]
CVE-2026-78593 debrief based on CVE Program and NIST NVD records. This medium-severity vulnerability in Kibana's Cribl integration allows authenticated users with Fleet management privileges to inject expressions into server-side script templates, potentially leading to unauthorized Elasticsearch ingest pipeline modifications. Affected product deployments should be assessed for exposure, prioritizing vali [truncated]
CVE-2026-78604 is an Incorrect Permission Assignment for Critical Resource vulnerability in Elastic Agent that can lead to local privilege escalation. On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their cho [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T15:17:41.277Z and has not been modified since then. The vulnerability is a Missing Authorization issue in Kibana, which can lead to information disclosure via Privilege Abuse. An authenticated user with elevated Kibana privileges can indirectly cause a background task to read from Elasticsearch i [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record CVE-2026-78600 was published on 2026-09-02T15:17:41.137Z and indicates an Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) that can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowin [truncated]
CVE-2026-78594 is a vulnerability in Elastic's APM Server, classified under CWE-409, Improper Handling of Highly Compressed Data. An authenticated user with write access to source map content can store specially crafted, highly compressed content that, when processed, exhausts the memory available to APM Server, leading to a persistent denial of service. The vulnerability has a CVSS score of 4.9 and is co [truncated]
A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges. This vulnerability, identified as CVE-2026-78591, is related to Path Traversal in the Kibana Fleet feature. The vulnerability allows unauthorized deletion of resource [truncated]
The CVE-2026-78590 vulnerability, classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory or 'Path Traversal'), affects the Kibana Fleet feature. This vulnerability allows a low-privileged user with Fleet Settings write access to potentially delete privileged resources, such as user accounts, by causing a subsequent administrative action to act on unintended internal resources. T [truncated]
An authenticated user with Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access. This Observable Response Discrepancy (CWE-204) can lead to information disclosure via Query System for Information (CAPEC-54). The Kibana Osquery feature is vulnerable, affecting Kibana administrators, security teams, and users with Osque [truncated]
A user with elevated privileges can submit a specially crafted request to Elasticsearch, causing excessive memory consumption and potentially rendering the affected node unavailable. This issue is classified as CWE-770, Allocation of Resources Without Limits or Throttling, and has a CVSS score of 4.9, indicating a medium severity. The vulnerability affects Elasticsearch versions 8.0.0 to 8.19.20 and 9.0.0 [truncated]
CVE-2026-78581 is an authorization bypass vulnerability in Kibana's AI Assistant feature, classified as CWE-639. An authenticated user with knowledge of a hard-to-guess conversation identifier could access or modify conversations they do not own. This vulnerability has a CVSS score of 4.2, indicating a MEDIUM severity level. Affected users should be aware and take steps to protect their instances. The CVE [truncated]
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and applies no bound to the length of the value being validated, so the validation causes the thread to exhaust its stack. The resulting fatal error is not handled by the surrounding execution pat [truncated]
A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a disproportionate amount of time, degrading the availability of indexing operations on the affected node.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:29.100Z and has not been modified since then. This vulnerability affects Elasticsearch, allowing an authenticated user with read privileges to submit a crafted search request, causing an out-of-memory condition and terminating the affected node process. The issue impacts Elasticsearch versi [truncated]
CVE-2026-72681 AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:28.853Z and has not been modified since then. Kibana Agent Builder does not correctly verify user privileges before creating and running tools that invoke separate Kibana feature functionality, allowing potential privilege escalation and disclosure of sensitive information. E [truncated]
CVE-2026-72677 is a Relative Path Traversal vulnerability in Kibana Fleet. The vulnerability exists because Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. These identifiers are stored as provided and later incorporated into requests when configurations are removed, potentially allowing attackers to manipulate these req [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:28.257Z and has not been modified since then. CVE-2026-72676 involves improper control of code generation in Fleet Server, allowing code injection attacks. Kibana accepted identifiers without restricting safe characters, which were then executed as part of server-side scripts during agent p [truncated]
The CVE-2026-72675 record describes a Missing Authorization vulnerability in Kibana's Machine Learning functionality, which can lead to cross-space information disclosure and unauthorized data modification. This issue arises because Kibana Machine Learning operations are carried out with elevated internal permissions and rely on a per-request space filter to keep machine learning data separated across dif [truncated]
A denial of service vulnerability was found in Kibana's Playground for RAG feature, which can be exploited through Excessive Allocation. This issue arises from the lack of bounds checking and deduplication in a user-supplied list of document fields. The vulnerability can lead to excessive allocation and resource exhaustion, resulting in a denial of service. The affected product context indicates that user [truncated]
CVE-2026-72673 is an Incorrect Authorization vulnerability in Elastic Kibana that allows an authenticated user with Synthetics write privilege in a single space to delete a private location used by other spaces, potentially disrupting monitoring capabilities. This occurs because the safeguard that prevents deletion of a private location still in use only evaluates monitors visible in the requesting user's [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:27.777Z and has not been modified since then. The NVD entry is currently Analyzed. The Elastic Security capability suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the acco [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:27.653Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Kibana's Machine Learning capability, allowing removal of saved objects, including trained models, without verifying sufficient privileges. A user with create anomaly detection jobs [truncated]
The CVE-2026-72669 vulnerability affects Kibana's Observability Onboarding flow, allowing authenticated users with generic read access to discover, read, and write arbitrary progress data. This could lead to unauthorized access and data manipulation, potentially causing server errors. The issue arises from the state stored for an Observability Onboarding flow not being bound to the user who created it. Ev [truncated]
A denial of service vulnerability via Excessive Allocation (CAPEC-130) in Kibana's Observability log analysis feature, with a CVSS score of 6.5 and MEDIUM severity, allows an authenticated user with minimal privileges to submit a specially crafted request, causing Kibana to perform an unbounded amount of concurrent work. This can exhaust the memory available to the Kibana process and make Kibana unavailab [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:27.157Z and has not been modified since then. This medium-severity vulnerability (CVE-2026-72666) in Kibana allows an authorized user to execute queries against Elastic Agents in a different space, potentially disclosing information from those hosts. The vulnerability occurs because Kibana [truncated]
The CVE-2026-72665 vulnerability in Kibana allows a user with the ability to author and evaluate Elastic Security detection rules to execute Osquery and Elastic Defend response actions on managed hosts without the required privileges. This can lead to unauthorized disclosure of information or changes to the state of affected hosts. Elastic Kibana users, administrators, and security teams should be aware o [truncated]
CVE-2026-72661 is a Missing Authorization issue in Kibana, allowing authenticated low-privileged users to read endpoint response action records with elevated internal permissions, potentially leading to information disclosure. This issue arises from an internal Kibana data retrieval capability used by Elastic Defend endpoint response actions that did not enforce the Security Solution and endpoint privileg [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:26.180Z and has not been modified since then. The CVE-2026-72659 vulnerability in Kibana's visualization feature allows an authenticated user with low-privileged access to cause unbounded memory growth, leading to a denial of service. The issue is caused by a specially crafted, malformed pa [truncated]
A Cross-Site Request Forgery (CWE-352) vulnerability exists in Kibana, which can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user permitted to create visualizations can save a specially crafted Vega visualization. When opened by another user, it causes authenticated requests to be issued to Kibana in the context of the viewing user's session. The vulnerability has a CVSS scor [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:25.870Z and has not been modified since then. The vulnerability, classified as CWE-639, Authorization Bypass Through User-Controlled Key, exists in Fleet Server. It allows an authenticated party with a valid enrolled agent credential to retrieve a policy the agent is not assigned to, potent [truncated]