Privilege Escalation Vulnerability in Kibana Fleet by Elastic
CVE-2026-72630

7.1HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72630?

A vulnerability in Kibana Fleet allows for privilege escalation due to incorrect authorization mechanisms. This flaw enables authenticated users with limited endpoint policy management privileges to alter integration policies inappropriately. When an existing policy is modified, the access restrictions should evaluate the replacement details, but instead, they assess the stored policy. This oversight means that users can potentially reconfigure and manage integration policies for different integrations without proper authority.

Affected Version(s)

Kibana 8.19.0 <= 8.19.19

Kibana 9.0.0 <= 9.4.4

Kibana 9.5.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.