CVE-2026-72680

MEDIUM CVSS 3.1: 6.5 EPSS 0.21%
Updated Aug 14, 2026
Kibana
Parameter Value
CVSS 6.5 (MEDIUM)
Type CWE-639 (Authorization Bypass)
Vendor Kibana
Public PoC No

Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. As a result, an authenticated user holding only the Agent Builder read privilege can supply an identifier already in use by another user in the same space and cause that user's conversation to be replaced and reassigned to the requesting account. The original owner permanently loses access to the conversation and its history.

The impact is limited to loss of integrity and availability of the affected conversation; the attacker does not read the overwritten content.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)