Incorrect authorization in Kibana - CVE-2026-72673
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to delete shared Synthetics private locations and disrupt availability monitoring in other spaces.
The vulnerability exists due to improper access control in the Synthetics private locations deletion functionality when handling deletion requests for private locations shared across multiple spaces. A remote user can delete a shared private location to delete shared Synthetics private locations and disrupt availability monitoring in other spaces.
Only deployments that use Synthetics private locations shared across more than one space are affected. Single-space deployments are not affected.