CVE-2026-72662
Received Received - Intake

Authorization Bypass in Kibana via Timeline Feature

Vulnerability report for CVE-2026-72662, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: Elastic

Description

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
elastic kibana *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana. An authenticated user with the Timeline feature privilege in a Kibana space can bypass access controls to enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access allows enumeration and disclosure, while write access enables modification and deletion.

Detection Guidance

This vulnerability requires detecting unauthorized access to Timeline objects in Kibana. Check Kibana logs for unusual Timeline object modifications or deletions. Review user permissions for the Timeline feature privilege in each space. Look for unexpected API calls to /api/timeline endpoints with user-controlled keys.

Impact Analysis

If you use Kibana with the Timeline feature, an attacker with access could read sensitive data, alter or delete draft timelines, or gain unauthorized access to information belonging to other users in your space. This could lead to data leaks, integrity issues, or loss of critical timeline records.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to personal or sensitive data, leading to potential breaches of GDPR (data protection) or HIPAA (health information privacy). Organizations may face penalties for failing to protect user data adequately.

Mitigation Strategies

Immediately review and restrict user privileges in Kibana spaces. Ensure only necessary users have Timeline feature privileges. Remove write access for users who only need read permissions to prevent unauthorized modification or deletion of draft Timeline objects.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72662. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart