
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-72681 is a Missing Authorization vulnerability in the Kibana Agent Builder component that allows authenticated low-privileged users to escalate privileges and access sensitive information they are not authorized to read. The flaw affects Kibana versions 9.4.0 through 9.4.3 (inclusive), with versions outside this range defaulting to unaffected status. It was published on August 13, 2026, with a patch available in Kibana 9.4.4. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is classified as CWE-862 (Missing Authorization): the Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before creating and running a tool that invokes that feature's functionality. An authenticated attacker with low-level privileges can craft requests to the Agent Builder that trigger restricted Kibana features without the necessary authorization checks being enforced. No user interaction is required, and the attack is conducted over the network with low complexity. No public proof-of-concept code has been identified at this time (GitHub Advisory, Elastic Advisory).
Successful exploitation allows any authenticated user with low-level privileges to bypass authorization controls within Kibana, effectively escalating their privileges to invoke restricted features and read sensitive information they are not authorized to access. The primary impact is a high confidentiality loss, with no direct integrity or availability impact. Depending on the data accessible through the invoked Kibana features, this could expose sensitive organizational data such as logs, monitoring data, or other information stored within the Elastic stack (GitHub Advisory, Elastic Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is approximately 0.252% (17th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment notes exploitation as "none" and the attack as not automatable (GitHub Advisory, Elastic Advisory).
Elastic has released Kibana 9.4.4 to address this vulnerability; users running versions 9.4.0 through 9.4.3 should upgrade immediately. As an interim workaround, administrators should restrict access to the Kibana Agent Builder functionality to only users who genuinely require it, using Kibana's role-based access control. Additionally, audit logs should be reviewed for any unauthorized access to sensitive features invoked through the Agent Builder tool (Elastic Advisory, GitHub Advisory).
Elastic published a security advisory (ESA-2026-83) on their community forum announcing the Kibana 9.4.4 update addressing this issue. Tenable has added detection coverage for this vulnerability in their plugin pipeline. No significant broader media coverage or notable researcher commentary has been identified beyond standard vulnerability tracking (Elastic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."