Privilege Escalation Vulnerability in Kibana Agent Builder by Elastic
CVE-2026-72668

7.3HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-72668?

The Kibana Agent Builder by Elastic contains a vulnerability that enables a non-administrative user to perform privileged operations by editing a shared agent. This could allow the user to execute actions under the identity of a higher-privileged user, thus enabling unauthorized modifications and full administrative access to the Kibana environment and the associated Elasticsearch cluster. When the same user can author workflows, the risk of escalating privileges is significantly heightened.

Affected Version(s)

Kibana 9.4.0 <= 9.4.6

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.