[NEW] [high] Kibana: Multiple vulnerabilities
A remote authenticated attacker can exploit multiple vulnerabilities in Kibana to disclose confidential information including credentials, manipulate data and configurations, bypass permissions and cause a Denial of Service.
CSIRTS triage
- What
- Multiple vulnerabilities in Kibana allow remote authenticated attackers to disclose credentials, manipulate configurations, bypass permissions, and cause denial of service.
- Who is affected
- Kibana deployments of unspecified versions accessible to authenticated users are affected.
- Urgency
- High urgency; multiple privilege escalation and data disclosure paths exist; remediation should be prioritized.
- Action
- Update Kibana to a patched version addressing CVE-2026-72629, CVE-2026-72630, CVE-2026-72631, CVE-2026-72632, CVE-2026-72643, CVE-2026-72650, CVE-2026-72651, and CVE-2026-72655.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Kibana
Get an email when a new Kibana advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2824
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-726290.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726300.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726310.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726320.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726430.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726500.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726510.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726550.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726580.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726590.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)cert-fr-avis
- mediumCVE-2026-72681: Kibana Agent Builder does not correctly verify that the requesting user holds the privileges r…nvd
- mediumCVE-2026-72680: Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation…nvd
- highCVE-2026-72675: Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and u…nvd
- mediumCVE-2026-72674: Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial …nvd
- mediumCVE-2026-72673: Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics pr…nvd
- highCVE-2026-72672: The Elastic Security capability that suggests existing field values while a user authors endpo…nvd
- mediumCVE-2026-72671: A Kibana Machine Learning capability that removes a saved object from the current space accept…nvd
- highCVE-2026-72670: A lower privileged user who holds only the privilege to read agent policies can read the entir…nvd
- highCVE-2026-72669: The state that Kibana stores for an Observability Onboarding flow is not bound to the user who…nvd
- mediumCVE-2026-72667: Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial …nvd
- mediumCVE-2026-72666: Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized …nvd
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17