Incorrect authorization in Kibana - CVE-2026-72673

 

Incorrect authorization in Kibana - CVE-2026-72673

Published: August 13, 2026


Vulnerability identifier: #VU142349
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72673
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete shared Synthetics private locations and disrupt availability monitoring in other spaces.

The vulnerability exists due to improper access control in the Synthetics private locations deletion functionality when handling deletion requests for private locations shared across multiple spaces. A remote user can delete a shared private location to delete shared Synthetics private locations and disrupt availability monitoring in other spaces.

Only deployments that use Synthetics private locations shared across more than one space are affected. Single-space deployments are not affected.


Affected software

Kibana

How to mitigate CVE-2026-72673

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.4

External References

Related Security Bulletins