CVE-2026-72658 PUBLISHED

Cross-Site Request Forgery in Kibana Leading to Privilege Escalation

Assigner: elastic
Reserved: 10.08.2026 Published: 13.08.2026 Updated: 14.08.2026

Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS Score: 7.3

Product Status

Vendor Elastic
Product Kibana
Versions Default: unaffected
  • affected from 8.19.0 to 8.19.19 (incl.)
  • affected from 9.0.0 to 9.4.4 (incl.)

References

Problem Types

  • CWE-352 Cross-Site Request Forgery CWE

Impacts

  • CAPEC-62 Cross Site Request Forgery