Kibana 8.19.20, and 9.4.5 Security Update (ESA-2026-96)

Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.

Affected Versions:

  • All versions from 8.5.0 up to and including 8.19.19
  • All versions from 9.0.0 up to and including 9.4.4

Affected Configurations:
Deployments that use the Elastic Security solution together with Osquery Manager or Elastic Defend are affected. Exposure to host-side impact requires enrolled agents; without enrolled Osquery or Elastic Defend agents no response action can reach a host.

Solutions and Mitigations:

The issue is resolved in versions 8.19.20, and 9.4.5.

For Users that Cannot Upgrade:

There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: High ( 8.1 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVE ID: CVE-2026-72665
Problem Type: CWE-862 - Missing Authorization
Impact: CAPEC-1 - Accessing Functionality Not Properly Constrained by ACLs