THREAT OPS › Threat News › [NVD] CVE-2026-72655 (MEDIUM 4.3) — Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges
[NVD] CVE-2026-72655 (MEDIUM 4.3) — Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges
CVE-2026-72655 CVSS: 4.3 MEDIUM Published: 2026-08-13T20:17:25.633
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges, via Manipulating User-Controlled Variables (CAPEC-
Indicators of compromise
- CVE-2026-72655cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72655