Missing Authorization in Kibana - CVE-2026-72669
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to missing authorization in Observability Onboarding flow state routes when handling read and update requests for onboarding state. A remote user can access onboarding flows created by other users and write arbitrary progress data to disclose sensitive information and modify data.
A tampered flow can cause the owner's onboarding view to fail with a server error.