VYPR

Kibana Agent Builder

by Elastic

CVEs (2)

  • CVE-2026-72681MedAug 13, 2026
    risk 0.42cvss 6.5epss

    Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of…

  • CVE-2026-72680MedAug 13, 2026
    risk 0.42cvss 6.5epss

    Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user.…