Aller au contenu

Fiche vulnérabilité

CVE-2026-72681 : faille élevée elastic kibana (CVSS 8.8)

Description

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
13 août 2026
Dernière mise à jour
3 sept. 2026

Produits concernés

  • elastic kibana

Références

Rechercher une autre vulnérabilité dans la base CVE