Authorization bypass through user-controlled key in Kibana - CVE-2026-72650
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through user-controlled key in alerting rule execution telemetry when accessing telemetry for alerting rules across Kibana spaces. A remote user can retrieve execution telemetry for spaces they are not authorized to access to disclose sensitive information.
The user must be authorized to read alerting rules in at least one Kibana space.