CVE-2026-72662: Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data

Published Sep 26, 2026
·
Updated

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.

Affected Software

1 affected component
Elastic Kibana

Event History

Sep 26, 2026
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Authenticated users who have the Timeline feature privilege in a Kibana space are affected by the authorization boundary failure for draft Timeline objects in that same space. The issue concerns access across users within a shared space.

2

What level of access is required to exploit it?

An attacker must be authenticated and granted the Timeline feature privilege in the target Kibana space. Timeline read access is enough to enumerate and disclose other users' draft Timeline objects; Timeline write access is required to modify or delete them.

3

What data or actions can be affected?

A user with Timeline read access can enumerate and read draft Timeline objects owned by other users in the same space. A user with Timeline write access can also modify or delete those objects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203