Kibana Agent Builder A2A JSON-RPC API Vulnerability Affecting Elastic
CVE-2026-72680

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72680?

The Kibana Agent Builder's A2A JSON-RPC API endpoint has a critical flaw that allows authenticated users, with only read privileges, to manipulate conversation identifiers. This oversight means users can unjustly claim ownership of conversations that belong to others, potentially leading to loss of integrity and access to conversations. As such, the rightful owners of these conversations permanently lose access to their content, affecting conversation integrity and availability without the ability for attackers to read the overwritten data.

Affected Version(s)

Kibana 9.2.0 <= 9.4.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.