Description
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it from every space it is shared with. The safeguard that prevented the deletion of a private location still in use evaluated only the monitors visible in the requesting user's own space, so monitors that depend on the private location in other spaces were not taken into account. As a result, an authenticated Kibana user holding the Synthetics write privilege in a single space could delete a private location that other spaces still depend on, even where the user has no access to those spaces. Deleting the private location removes the shared configuration and stops the monitors in the other spaces from running, which suppresses the availability monitoring those spaces rely on.
Published: 2026-08-13
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect authorization flaw (CWE‑863) in Kibana allows an authenticated user who has Synthetics write rights in a single space to delete a private location that is shared with other spaces. When the private location is removed, the shared configuration is lost and all monitors in every space that reference it are stopped. The loss of these monitors disables availability monitoring for those spaces and prevents stakeholders from detecting outages, harming service reliability.

Affected Systems

Elastic Kibana instances that include the Synthetics feature and provide write privileges to users are affected. All deployments containing the code path that implements the deletion logic are impacted; no specific version numbers are asserted in the CVE data.

Risk and Exploitability

The CVSS score of 5.4 classifies the flaw as moderate severity. EPSS is unavailable, so the estimated exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user with Synthetics write permission, which requires legitimate login credentials or a compromised account. Once exploited, the attacker can cause availability disruptions by disabling monitors across multiple spaces.

Generated by OpenCVE AI on August 13, 2026 at 21:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch that resolves the incorrect authorization bug in Kibana.
  • Restrict Synthetics write privileges to only trusted users and roles to reduce the attack surface.
  • After patching, review private locations that are shared across spaces and reconfigure monitors so that no unintended deletion can occur, ensuring all spaces maintain proper availability monitoring.

Generated by OpenCVE AI on August 13, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it from every space it is shared with. The safeguard that prevented the deletion of a private location still in use evaluated only the monitors visible in the requesting user's own space, so monitors that depend on the private location in other spaces were not taken into account. As a result, an authenticated Kibana user holding the Synthetics write privilege in a single space could delete a private location that other spaces still depend on, even where the user has no access to those spaces. Deleting the private location removes the shared configuration and stops the monitors in the other spaces from running, which suppresses the availability monitoring those spaces rely on.
Title Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private Locations
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:32:40.033Z

Reserved: 2026-08-10T11:17:49.704Z

Link: CVE-2026-72673

cve-icon Vulnrichment

Updated: 2026-08-13T20:32:36.429Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:27.893

Modified: 2026-08-28T15:32:26.217

Link: CVE-2026-72673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:00:05Z

Weaknesses