CVE-2026-72662 - Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data
Brief
CVE ID : CVE-2026-72662
Published : Sept. 26, 2026, 8:42 p. m.
- 19 minutes ago
Description : Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space.
Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.
Severity: 6.3
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
