Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve alerting rule execution telemetry that belongs to spaces the user is not authorized to access. The disclosed telemetry includes rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters.
Published: 2026-08-13
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Kibana allows an authenticated user with read access to alerting rule configurations in a single space to retrieve alerting rule execution telemetry for spaces they are not authorized to access. The disclosed telemetry contains rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters, exposing sensitive operational data. This flaw is due to a user‑controlled key that is not properly validated against access control lists and is classified as CWE‑639.

Affected Systems

Elastic Kibana is affected; the specific product is Kibana by Elastic. No version information is provided in the current data, so all released Kibana versions could be vulnerable until an official patch is released.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, and no EPSS score is available, suggesting low likelihood of exploitation. The vulnerability is not listed in CISA KEV. An attacker needs only an authenticated account with limited privileges to exploit the flaw, allowing data leakage but not full system compromise. The primary risk is confidentiality for internal telemetry, which could assist attackers in mapping business processes or identifying configuration weaknesses.

Generated by OpenCVE AI on August 13, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana security update released by Elastic that addresses the authorization bypass in alert rule telemetry.
  • Limit user permissions so that read access to alerting rules is granted only for the spaces where it is explicitly required, ensuring ACL checks are enforced on all telemetry data.
  • Continuously monitor Kibana audit logs for accesses to rule execution telemetry and investigate any unauthorized attempts promptly.

Generated by OpenCVE AI on August 13, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve alerting rule execution telemetry that belongs to spaces the user is not authorized to access. The disclosed telemetry includes rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters.
Title Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:30:22.688Z

Reserved: 2026-08-10T11:17:38.893Z

Link: CVE-2026-72650

cve-icon Vulnrichment

Updated: 2026-08-13T20:30:19.101Z

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:25.280

Modified: 2026-08-13T21:18:10.030

Link: CVE-2026-72650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key