THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-72655 (MEDIUM 4.3) — Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges

[NVD] CVE-2026-72655 (MEDIUM 4.3) — Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges

mednvdPublished 2026-08-13

CVE-2026-72655 CVSS: 4.3 MEDIUM Published: 2026-08-13T20:17:25.633

Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges, via Manipulating User-Controlled Variables (CAPEC-

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72655