Authorization Bypass in Kibana Agent Builder by Elastic
CVE-2026-72643

7.1HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72643?

The Kibana Agent Builder contains a flaw that allows for unauthorized access to private agent configurations. By relying on a non-unique username across different Elasticsearch authentication realms, the system fails to verify ownership correctly. This can lead to unauthorized users altering or removing agent configurations they do not own, potentially compromising the integrity and security of the functionalities associated with those agents.

Affected Version(s)

Kibana 9.4.0 <= 9.4.4

Kibana 9.5.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.