Junglewise Threat Intelligence

CVE-2026-72662: Elastic Kibana authorization bypass in Timeline feature

CVE-2026-72662 · Severity: medium · CVSS 6.3 · Published 2026-09-26

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

An authorization flaw in Kibana's Timeline feature allows authenticated users to access, modify, and delete draft Timeline data belonging to other users within the same space. An attacker with Timeline privileges can view sensitive investigation data created by colleagues, alter findings, or destroy timeline objects, potentially compromising security investigations and evidence integrity.

Technical details

An authorization bypass vulnerability (CWE-639) in Kibana's Timeline feature fails to properly constrain access controls on draft Timeline objects. Authenticated users with Timeline read privilege can enumerate and disclose other users' draft Timelines; those with write privilege can also modify or delete them. The vulnerability requires authentication and Timeline feature privilege in a Kibana space but does not require user interaction.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.21; 9.4.0 to 9.4.5

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: Fixed in Kibana 8.19.22 and 9.4.6

References

Related threats