CVE-2026-72681: Elastic Kibana

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.

Affected products

  • Elastic Kibana: from 9.4.0, before 9.4.4 (fixed in 9.4.4)

Published 2026-08-13. Last modified 2026-09-03.