A vulnerability labeled as problematic has been found in Elastic Kibana up to 8.19.19/9.4.4. Affected by this vulnerability is an unknown functionality of the component Case Management API. Such manipulation leads to dynamically-determined object attributes.

This vulnerability is referenced as CVE-2026-72655. It is possible to launch the attack remotely. No exploit is available.