AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72650

MEDIUM · CVSS 4.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Kibana is vulnerable to an authorization bypass that allows authenticated users to access alerting rule execution telemetry from spaces they should not have permission to view. This can lead to unauthorized information disclosure, including sensitive data such as rule identifiers and execution outcomes. Organizations using Kibana, particularly those managing multiple spaces with varying access controls, should prioritize addressing this vulnerability to protect sensitive telemetry data.

CVE
CVE-2026-72650
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve alerting rule execution telemetry that belongs to spaces the user is not authorized to access. The disclosed telemetry includes rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters.