CVE-2026-72658: Cross-Site Request Forgery in Kibana Leading to Privilege Escalation
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72658?
The severity of CVE-2026-72658 is rated high with a score of 7.3.
How do I fix CVE-2026-72658?
To fix CVE-2026-72658, ensure that you update Kibana to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-72658?
CVE-2026-72658 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to privilege escalation.
What are the impacts of CVE-2026-72658?
The impacts of CVE-2026-72658 include the potential to escalate privileges for users who exploit the CSRF vulnerability.
Who is affected by CVE-2026-72658?
Users of Kibana who are permitted to create visualizations could be affected by CVE-2026-72658.