Kibana 9.1.x < 9.4.5 Multiple Vulnerabilities (ESA-2026-97 / ESA-2026-89)

high Nessus Plugin ID 338736

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Kibana installed on the remote host is 9.1.x prior to 9.4.5. It is, therefore, affected by multiple vulnerabilities as referenced in the ESA-2026-89 and ESA-2026-97 advisories.

- The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts. (CVE-2026-72672)

- Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery live queries in one space can have a query carried out on hosts belonging to another space, resulting in disclosure of information from those hosts to the Osquery results data stream.
(CVE-2026-72666)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update to Kibana version 9.4.5 or later.

See Also

http://www.nessus.org/u?02cb6f56

http://www.nessus.org/u?5619e249

Plugin Details

Severity: High

ID: 338736

File Name: kibana_esa_2026_97.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.58

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-72672

CVSS v3

Risk Factor: High

Base Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Vulnerability Information

CPE: cpe:/a:elasticsearch:kibana

Required KB Items: installed_sw/Kibana

Patch Publication Date: 8/13/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-72666, CVE-2026-72672

CWE: 639, 863

IAVB: 2026-B-0232