Unauthorized Modification Vulnerability in Elastic Security Case Management
CVE-2026-72655

4.3MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72655?

In the case management functionality of Elastic Security within Kibana, a vulnerability exists that allows authenticated users without editing privileges to modify case data. This happens due to inadequate authorization enforcement on object attributes in the case management API, which enables low-privileged users to alter case records they should only be able to view. This flaw can potentially lead to unauthorized manipulation of sensitive information.

Affected Version(s)

Kibana 8.0.0 <= 8.19.19

Kibana 9.0.0 <= 9.4.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.