Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.
Published: 2026-09-26
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure, modification, or deletion of data via privilege escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an authorization bypass through a user‑controlled key that allows an authenticated user with the Timeline feature privilege in a Kibana space to enumerate, read, modify, and delete draft Timeline objects belonging to other users. Read access alone is sufficient for discovery and disclosure, while write access lets the attacker alter or delete the data. This elevates the user's effective permissions beyond what their role intends, exposing sensitive data and disrupting user workflows.

Affected Systems

Elastic’s Kibana product is affected, specifically any instance where users are granted Timeline feature privileges within a space. The vulnerability arises when ACL restrictions around timeline object access are not properly enforced, regardless of the specific Kibana version present. Affected deployments include all configurations that enable the Timeline feature and provide users with read or write access within shared spaces. The specific Kibana version affected is unknown or not disclosed.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate impact level. EPSS is not available, so the exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation at this time. However, the likely attack vector involves an authenticated user exploiting their legitimate access to the Timeline feature; enumeration and disclosure are possible with read privileges, while modification and deletion require write privileges. Because the flaw stems from an improperly constrained ACL, users with even minimal permissions can gain more control than intended.

Generated by OpenCVE AI on September 26, 2026 at 22:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to the latest patched release once available
  • Restrict Timeline read and write privileges to only the roles that truly need them
  • Audit and enforce granular ACLs on spaces to ensure timeline objects are isolated per user
  • If immediate remediation is not possible, disable the Timeline feature in high‑risk spaces while monitoring for anomalous activity

Generated by OpenCVE AI on September 26, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 26 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Sat, 26 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.
Title Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-26T23:01:33.512Z

Reserved: 2026-08-10T11:17:45.102Z

Link: CVE-2026-72662

cve-icon Vulnrichment

Updated: 2026-09-26T23:01:29.967Z

cve-icon NVD

Status : Received

Published: 2026-09-26T21:16:55.410

Modified: 2026-09-26T23:16:35.093

Link: CVE-2026-72662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T23:00:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key