PatchSiren cyber security CVE debrief
CVE-2026-72650 Elastic CVE debrief
CVE-2026-72650 is an authorization bypass vulnerability in Kibana, allowing authenticated users to access alerting rule execution telemetry across spaces they are not authorized for. The disclosed telemetry includes rule identifiers, names, space identifiers, execution outcomes, timestamps, and counters. This vulnerability can be mitigated by restricting access to alerting rule execution telemetry based on user authorization and implementing additional monitoring. Elastic Kibana administrators and users, security teams monitoring for potential unauthorized access to alerting rule execution telemetry, and operators responsible for maintaining Kibana spaces and access controls should be aware of this vulnerability. They should review and update Kibana configurations to restrict access and implement additional monitoring to detect and respond to potential unauthorized access attempts. Vulnerability management and security teams should also prioritize patching and mitigation efforts to prevent exploitation of this vulnerability in their environments, considering the potential impact on their security posture and the sensitivity of the data that could be accessed by exploiting this vulnerability.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-02
Who should care
Elastic Kibana administrators and users, security teams monitoring for potential unauthorized access to alerting rule execution telemetry, and operators responsible for maintaining Kibana spaces and access controls should be aware of this vulnerability. They should review and update Kibana configurations to restrict access and implement additional monitoring to detect and respond to potential unauthorized access attempts. Vulnerability management and security teams should also prioritize patching and mitigation efforts to prevent exploitation of this vulnerability in their environments, considering the potential impact on their security posture and the sensitivity of the data that could be accessed by exploiting this vulnerability. This includes ensuring that Kibana spaces are properly configured to enforce access controls and that users are aware of the potential risks associated with this vulnerability. Furthermore, asset inventory management and change management processes should be reviewed to ensure that affected systems are identified and prioritized for remediation. Monitoring and detection capabilities should also be evaluated to ensure they can detect potential exploitation attempts and unauthorized access to alerting rule execution telemetry. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their Kibana deployments from potential exploitation. Additionally, it is crucial for security teams to stay informed about the latest developments regarding this vulnerability and to be prepared to respond quickly in case of an attack. This involves staying up-to-date with vendor advisories, security bulletins, and other relevant information sources to ensure that they have the necessary knowledge and resources to effectively manage the risks associated with this vulnerability. Effective communication and collaboration between security teams, IT operations, and other stakeholders are also essential to ensure a coordinated and efficient response to this vulnerability. By prioritizing awareness, preparedness, and proactive security measures, organizations can minimize the potential impact of this vulnerability on
Technical summary
CVE-2026-72650 is an authorization bypass vulnerability in Kibana that allows an authenticated user, authorized to read alerting rules in one space, to retrieve execution telemetry of alerting rules from spaces they are not authorized to access. The disclosed telemetry includes rule identifiers, names, space identifiers, execution outcomes, timestamps, and counters. This vulnerability can be mitigated by restricting access to alerting rule execution telemetry based on user authorization and implementing additional monitoring.
Defensive priority
Authenticated users with limited authorization could potentially access sensitive alerting rule execution telemetry across different Kibana spaces.
Recommended defensive actions
- Review and update Kibana configurations to restrict access to alerting rule execution telemetry based on user authorization.
- Implement additional monitoring to detect and respond to potential unauthorized access attempts.
- Ensure Kibana spaces are properly configured to enforce access controls.
- Verify Kibana configurations and check for unauthorized access attempts.
- Review user authorization and monitor for suspicious activity.
- Conduct asset inventory management and change management processes to identify and prioritize affected systems for remediation.
- Stay informed about the latest developments regarding this vulnerability and be prepared to respond quickly in case of an attack.
Evidence notes
The CVE-2026-72650 record indicates an authorization bypass vulnerability in Kibana, allowing authenticated users to access alerting rule execution telemetry across spaces they are not authorized for. Evidence is based on official CVE and NVD records. To verify, defenders should review Kibana configurations, check for unauthorized access attempts, and ensure proper space configuration. Additional verification steps include reviewing user authorization and monitoring for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72650 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72650
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72650 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72650
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-105/389521
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.