Authorization Bypass in Kibana Agent Builder by Elastic
CVE-2026-72643
7.1HIGH
What is CVE-2026-72643?
The Kibana Agent Builder contains a flaw that allows for unauthorized access to private agent configurations. By relying on a non-unique username across different Elasticsearch authentication realms, the system fails to verify ownership correctly. This can lead to unauthorized users altering or removing agent configurations they do not own, potentially compromising the integrity and security of the functionalities associated with those agents.
Affected Version(s)
Kibana 9.4.0 <= 9.4.4
Kibana 9.5.0