Unauthorized Modification Vulnerability in Elastic Security Case Management
CVE-2026-72655
4.3MEDIUM
What is CVE-2026-72655?
In the case management functionality of Elastic Security within Kibana, a vulnerability exists that allows authenticated users without editing privileges to modify case data. This happens due to inadequate authorization enforcement on object attributes in the case management API, which enables low-privileged users to alter case records they should only be able to view. This flaw can potentially lead to unauthorized manipulation of sensitive information.
Affected Version(s)
Kibana 8.0.0 <= 8.19.19
Kibana 9.0.0 <= 9.4.4