CVE-2026-72662: Elastic Kibana

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.

Affected products

  • Elastic Kibana: from 8.0.0, up to and including 8.19.21; from 9.4.0, up to and including 9.4.5

Published 2026-09-26. Last modified 2026-09-28.