No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 13 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic kibana |
|
| Vendors & Products |
Elastic
Elastic kibana |
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in different realms are treated as the same owner. This discloses the configuration and instructions of an agent the caller does not own, and allows that agent to be altered or removed. | |
| Title | Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-08-13T20:27:50.500Z
Reserved: 2026-08-10T11:17:35.480Z
Link: CVE-2026-72643
Updated: 2026-08-13T20:27:46.836Z
Status : Received
Published: 2026-08-13T20:17:24.807
Modified: 2026-08-13T21:18:09.593
Link: CVE-2026-72643
No data.
OpenCVE Enrichment
Updated: 2026-08-13T21:00:06Z