A vulnerability, which was classified as problematic , was found in Elastic Kibana up to 8.19.18/9.3.7/9.4.3 . Impacted is an unknown function of the component Elastic Defend endpoint response actions . The manipulation results in missing authorization. This vulnerability is known as CVE-2026-72661 . It is possible to launch the attack remotely. No exploit is available.