User State Exposure and Unauthorized Data Manipulation in Kibana by Elastic
CVE-2026-72669

7.6HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72669?

The Kibana platform experiences a vulnerability in its Observability Onboarding flow, where stored state data is not tied to the user who created it. This oversight allows an authenticated user with mere read access to view and modify the onboarding processes of other users. As a result, they can access sensitive data and potentially corrupt other users' onboarding views, triggering server errors. This vulnerability raises significant concerns regarding user privacy and data integrity within Kibana.

Affected Version(s)

Kibana 8.9.0 <= 8.19.18

Kibana 9.0.0 <= 9.4.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.