User State Exposure and Unauthorized Data Manipulation in Kibana by Elastic
CVE-2026-72669
7.6HIGH
What is CVE-2026-72669?
The Kibana platform experiences a vulnerability in its Observability Onboarding flow, where stored state data is not tied to the user who created it. This oversight allows an authenticated user with mere read access to view and modify the onboarding processes of other users. As a result, they can access sensitive data and potentially corrupt other users' onboarding views, triggering server errors. This vulnerability raises significant concerns regarding user privacy and data integrity within Kibana.
Affected Version(s)
Kibana 8.9.0 <= 8.19.18
Kibana 9.0.0 <= 9.4.4