THREAT OPS › Threat News › [NVD] CVE-2026-72672 (HIGH 7.7) — The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are veri
[NVD] CVE-2026-72672 (HIGH 7.7) — The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are veri
CVE-2026-72672 CVSS: 7.7 HIGH Published: 2026-08-13T20:17:27.777
The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-72672cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72672