MEDIUMVulnerability

CVE-2026-72661

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its user-facing equivalents require, and it retrieved data with elevated internal permissions rather than the permissions of the requesting user. As a result, an authenticated low-privileged Kibana user with no Security Solution privileges, endpoint privileges and no Elasticsearch privileges on the underlying data, could read endpoint response action records and the corresponding response content returned by managed hosts.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00278
cve_id
CVE-2026-72661
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-13T20:17:26.453
last_modified
2026-09-02T14:13:13.037
epss_percentile
0.19897

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72661 — Ninja Signal Threat Intelligence | Ninja Signal