Multiple vulnerabilities in Elastic Kibana (August 14, 2026)
Multiple vulnerabilities have been discovered in Elastic Kibana. Some of them allow an attacker to cause privilege escalation, remote denial of service and data confidentiality breach.
CSIRTS triage
- What
- Multiple vulnerabilities in Kibana enable privilege escalation, denial of service, and data confidentiality breaches.
- Who is affected
- All deployments of Elastic Kibana running affected versions.
- Urgency
- High; privilege escalation and data breach risks warrant immediate remediation.
- Action
- Apply the security update from Elastic for the affected Kibana version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Kibana
Get an email when a new Kibana advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1020/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-726590.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726320.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726430.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726750.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726550.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726650.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726630.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726290.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726690.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-726660.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Kibana: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Kibana: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-72681: Kibana Agent Builder does not correctly verify that the requesting user holds the privileges r…nvd
- mediumCVE-2026-72680: Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation…nvd
- highCVE-2026-72677: Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana res…nvd
- highCVE-2026-72675: Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and u…nvd
- mediumCVE-2026-72674: Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial …nvd
- mediumCVE-2026-72673: Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics pr…nvd
- highCVE-2026-72672: The Elastic Security capability that suggests existing field values while a user authors endpo…nvd
- mediumCVE-2026-72671: A Kibana Machine Learning capability that removes a saved object from the current space accept…nvd
- highCVE-2026-72670: A lower privileged user who holds only the privilege to read agent policies can read the entir…nvd
- highCVE-2026-72669: The state that Kibana stores for an Observability Onboarding flow is not bound to the user who…nvd
Recent advisories for Elastic Kibana
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-72672: The Elastic Security capability that suggests existing field values while a user authors endpo…nvd · 2026-08-13
- mediumCVE-2026-72666: Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized …nvd · 2026-08-13
- highCVE-2026-72665: Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and El…nvd · 2026-08-13
- mediumCVE-2026-72664: Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend…nvd · 2026-08-13
- mediumCVE-2026-72655: Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in th…nvd · 2026-08-13
- highCVE-2026-72632: Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excava…nvd · 2026-08-13
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Mattermost products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Ubuntu Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Red Hat Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14