Vulnerability Description
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 8.0.0, < 8.19.20 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-9Vendor AdvisoryMitigation
FAQ
What is CVE-2026-72658?
CVE-2026-72658 is a vulnerability with a CVSS score of 7.3 (HIGH). Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted...
How severe is CVE-2026-72658?
CVE-2026-72658 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72658?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Kibana.