---
cve: "CVE-2026-72662"
severity: "MEDIUM"
cvss: 6.3
epss: "0.2%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-09-26 21:16:55"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-30T02:34:18+02:00"
---

# CVE-2026-72662

> 6.3 MEDIUM

## Beschreibung

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.

## CNA-Record (Kanon, cvelistV5)

- CNA: **elastic**
- State: PUBLISHED
- Stand: 2026-09-26 23:01:33
- CNA-CVSS: **6.3** (`CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Gering | warn |

## Schwachstellen-Klasse

- **CWE-639** — Authorization Bypass Through User-Controlled Key
  The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

## BSI-Hinweise (deutsch)

- [Kibana: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3575) — _BSI-Einstufung: mittel_
  Ein Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um seine Privilegien zu erhöhen, und um einen Denial of Service Angriff durchzuführen.

## Referenzen

- <https://discuss.elastic.co/t/kibana-8-19-22-9-4-6-security-update-esa-2026-103/390679>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-72662) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
