Authorization bypass through user-controlled key in Kibana - CVE-2026-72662

 

Authorization bypass through user-controlled key in Kibana - CVE-2026-72662

Published: September 25, 2026


Vulnerability identifier: #VU152230
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72662
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose, modify, or delete data.

The vulnerability exists due to authorization bypass through a user-controlled key in the Security Solution Timeline feature when accessing draft Timeline objects in the same Kibana space. A remote user can enumerate, read, modify, or delete draft Timeline objects belonging to other users to disclose, modify, or delete data.

Read access is sufficient for enumeration and disclosure, while the Timeline write privilege is required for modification and deletion.


Affected software

Kibana

How to mitigate CVE-2026-72662

Install security update from vendor's website.

Kibana - addressed in versions 8.19.22, 9.4.6

External References

Related Security Bulletins