Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in different realms are treated as the same owner. This discloses the configuration and instructions of an agent the caller does not own, and allows that agent to be altered or removed. | |
| Title | Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-08-13T20:27:50.500Z
Reserved: 2026-08-10T11:17:35.480Z
Link: CVE-2026-72643
No data.
Status : Received
Published: 2026-08-13T20:17:24.807
Modified: 2026-08-13T20:17:24.807
Link: CVE-2026-72643
No data.
OpenCVE Enrichment
No data.