CVE-2026-72662
EUVD-2026-8779326.09.2026, 21:16
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | kibana | 8.0.0 ≤ 𝑥 ≤ 8.19.21 | CNA |
| elastic | kibana | 9.4.0 ≤ 𝑥 ≤ 9.4.5 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure