Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.
Affected Versions:
All versions from 8.9.0 up to and including 8.19.19
All versions from 9.0.0 up to and including 9.4.4
Affected Configurations:
Deployments that use the Elastic Security solution with Elastic Defend agents enrolled.
Solutions and Mitigations:
The issue is resolved in versions 8.19.20, and 9.4.5.
For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.
Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.
Elastic Cloud Serverless
Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.
Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVE ID: CVE-2026-72664
Problem Type: CWE-862 - Missing Authorization
Impact: CAPEC-1 - Accessing Functionality Not Properly Constrained by ACLs