CVE-2026-72669: Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tampering
The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover the onboarding flows of other users, read their onboarding state, and write arbitrary progress data into them. A tampered flow can also cause the owner's onboarding view to fail with a server error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72669?
The severity of CVE-2026-72669 is rated high with a score of 7.6.
How do I fix CVE-2026-72669?
To fix CVE-2026-72669, update your Elastic Kibana installation to the latest version that addresses this vulnerability.
What type of attack does CVE-2026-72669 allow?
CVE-2026-72669 allows for cross-user information disclosure and potential data tampering due to missing authorization.
Which software is affected by CVE-2026-72669?
CVE-2026-72669 affects Elastic Kibana, specifically versions prior to the security update.
What is the impact of CVE-2026-72669 on users?
The impact of CVE-2026-72669 allows authenticated users to access and manipulate onboarding flows they should not be able to see.