Kibana 9.4.x < 9.4.5 / 9.5.x < 9.5.1 Incorrect Authorization (ESA-2026-124)

high Nessus Plugin ID 338735

Synopsis

The remote host is affected by an incorrect authorization vulnerability.

Description

The version of Kibana installed on the remote host is 9.4.x prior to 9.4.5, or 9.5.x prior to 9.5.1. It is, therefore, affected by a vulnerability as referenced in the ESA-2026-124 advisory.

- Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in different realms are treated as the same owner. This discloses the configuration and instructions of an agent the caller does not own, and allows that agent to be altered or removed. (CVE-2026-72643)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update to Kibana version 9.4.5, 9.5.1 or later.

See Also

http://www.nessus.org/u?f9851340

Plugin Details

Severity: High

ID: 338735

File Name: kibana_esa_2026_124.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.8

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:N

CVSS Score Source: CVE-2026-72643

CVSS v3

Risk Factor: High

Base Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Vulnerability Information

CPE: cpe:/a:elasticsearch:kibana

Required KB Items: installed_sw/Kibana

Patch Publication Date: 8/13/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-72643

CWE: 863

IAVB: 2026-B-0232