External risk intelligence

Elastic Kibana Fleet Server Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-72676

Kibana is commonly deployed as a web-based management, analytics, and visualization interface. It is frequently accessed over the network by users or integrated into external-facing service monitoring architectures, making the application surface and its associated management components, such as Fleet Server, commonly reachable in many deployment environments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Fleet Server, which is part of Kibana, could allow an attacker to inject and execute malicious scripts. This happens because the system does not properly validate identifiers used in server-side scripts during agent policy processing, potentially leading to unauthorized code execution.

  • Code injection flaw in Fleet Server technology.
  • Matters due to potential for unauthorized script execution.
  • Confirm relevance and exposure are the main concerns.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted identifier to Kibana, which is then processed by Fleet Server. This identifier, when embedded within a server-side script during agent policy setup, allows the attacker's script content to be executed. This could lead to unauthorized code execution on the server.

  • No authentication or user interaction required.
  • Vulnerable component processes attacker-controlled identifier.
  • Risk of attacker-supplied script execution.

Live Threat

Current exploitation, exposure, and threat context

Fleet Server, when processing agent policies, could execute attacker-supplied script content if a specially crafted identifier is provided for an output configuration. This occurs because the identifier is embedded directly into a server-side script without proper sanitization, allowing script syntax to be interpreted as executable code rather than data.

  • Server-side scripts and agent policy processing.
  • An identifier in an output configuration.
  • Execution of unauthorized script content.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners, likely within infrastructure or platform teams managing Kibana and Fleet Server, are responsible for addressing this critical code injection vulnerability. The immediate priority is to identify all instances of the affected Kibana versions, confirm their exposure and criticality, and then coordinate remediation efforts. This may involve vendor engagement with Elastic and careful planning for maintenance windows or implementing temporary compensating controls to mitigate risk until a permanent fix can be applied.

  • Confirm Kibana and Fleet Server ownership.
  • Verify exposure and business criticality.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Kibana and its role in Fleet Server?

Kibana is a web-based interface used for searching, visualizing, and managing data within the Elastic Stack. Fleet Server acts as a component within this ecosystem to manage and monitor elastic agents across infrastructure. It relies on Kibana to configure policies and settings for these agents, making it a central point for administrative control over data collection.

How does CVE-2026-72676 cause code injection?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). It occurs because Kibana does not filter special characters when creating identifiers for output configurations. When Fleet Server processes these policies, it treats the untrusted identifier as part of a server-side script. Because the system fails to distinguish between data and instructions, the injected code is executed on the server.

What triggers this Fleet Server vulnerability?

The flaw is triggered when an attacker provides a specially crafted identifier for an output configuration that Kibana then processes. It is important to note that this does not require authentication or user interaction. If the input contains malicious script syntax, it will be executed during routine agent policy processing. Standard, benign identifiers that do not contain script-altering syntax do not trigger the injection.

Is my Kibana instance at risk?

According to Halo Surface Signal, Kibana is often deployed as a web-based interface that is reachable over a network, frequently serving as an external-facing management component. If your instance is accessible via the network, the potential for unauthorized access is higher. You should assess whether your Kibana deployment is exposed to untrusted networks or if it operates within a restricted internal environment.

How should I respond to this threat?

Begin by identifying all Kibana versions in your environment to determine if they fall within the affected ranges. Once identified, prioritize these instances based on their network exposure and business criticality. Coordinate with your platform teams to apply the vendor-supplied updates. If an immediate patch is not possible, investigate temporary configuration controls to limit access to the affected management interfaces.

References