Junglewise Threat Intelligence

CVE-2026-72650: Elastic Kibana authorization bypass in alerting rules

CVE-2026-72650 · Severity: medium · CVSS 4.3 · Published 2026-08-13

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data analytics and visualization platform used to search and analyze data from Elasticsearch. An authenticated user with permission to view alerting rules in one workspace can bypass access controls to view execution details and telemetry from alerting rules in other workspaces they should not access, potentially exposing sensitive operational information.

Technical details

This vulnerability is an authorization bypass (CWE-639) affecting Kibana's alerting rules feature. An authenticated, low-privileged user authorized to read alerting rules in a single Kibana space can craft requests using user-controlled parameters to retrieve alerting rule execution telemetry from other spaces outside their authorization scope. The attack requires authentication and network access to Kibana, with no user interaction needed. An attacker can disclose rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters from unauthorized spaces. The vulnerability is resolved in versions 8.19.20 and 9.4.5; no workarounds are available for unpatched systems.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.19, 9.0.0 to 9.4.4

Timeline

  • 2026-08-13: disclosed: Security advisory ESA-2026-105 published
  • 2026-08-13: patched: Fix released in versions 8.19.20 and 9.4.5

References

Related threats