{"id":"CVE-2026-72662","title":"Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1)","summary":"Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user gr…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-639"],"vendor":"Elastic","product":"Kibana","affected":["Kibana >= 8.0.0 <= 8.19.21","Kibana >= 9.4.0 <= 9.4.5"],"published":"2026-09-26","updated":"2026-09-26","sourceUpdated":"2026-09-26T23:16:35.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72662","references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-22-9-4-6-security-update-esa-2026-103/390679","label":"security@elastic.co"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-26T23:01:25.142449Z"},"ingestedAt":"2026-09-26T21:38:01.501Z","slug":"CVE-2026-72662","body":"## Overview\n\nAuthorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}