Authorization bypass through user-controlled key in Kibana - CVE-2026-72662
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose, modify, or delete data.
The vulnerability exists due to authorization bypass through a user-controlled key in the Security Solution Timeline feature when accessing draft Timeline objects in the same Kibana space. A remote user can enumerate, read, modify, or delete draft Timeline objects belonging to other users to disclose, modify, or delete data.
Read access is sufficient for enumeration and disclosure, while the Timeline write privilege is required for modification and deletion.