Privilege Escalation Vulnerability in Kibana Fleet by Elastic
CVE-2026-72630
7.1HIGH
What is CVE-2026-72630?
A vulnerability in Kibana Fleet allows for privilege escalation due to incorrect authorization mechanisms. This flaw enables authenticated users with limited endpoint policy management privileges to alter integration policies inappropriately. When an existing policy is modified, the access restrictions should evaluate the replacement details, but instead, they assess the stored policy. This oversight means that users can potentially reconfigure and manage integration policies for different integrations without proper authority.
Affected Version(s)
Kibana 8.19.0 <= 8.19.19
Kibana 9.0.0 <= 9.4.4
Kibana 9.5.0