Authorization bypass through user-controlled key in Kibana - CVE-2026-72650

 

Authorization bypass through user-controlled key in Kibana - CVE-2026-72650

Published: August 13, 2026


Vulnerability identifier: #VU142347
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72650
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through user-controlled key in alerting rule execution telemetry when accessing telemetry for alerting rules across Kibana spaces. A remote user can retrieve execution telemetry for spaces they are not authorized to access to disclose sensitive information.

The user must be authorized to read alerting rules in at least one Kibana space.


Affected software

Kibana

How to mitigate CVE-2026-72650

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.5

External References

Related Security Bulletins