PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72650 Elastic CVE debrief

CVE-2026-72650 is an authorization bypass vulnerability in Kibana, allowing authenticated users to access alerting rule execution telemetry across spaces they are not authorized for. The disclosed telemetry includes rule identifiers, names, space identifiers, execution outcomes, timestamps, and counters. This vulnerability can be mitigated by restricting access to alerting rule execution telemetry based on user authorization and implementing additional monitoring. Elastic Kibana administrators and users, security teams monitoring for potential unauthorized access to alerting rule execution telemetry, and operators responsible for maintaining Kibana spaces and access controls should be aware of this vulnerability. They should review and update Kibana configurations to restrict access and implement additional monitoring to detect and respond to potential unauthorized access attempts. Vulnerability management and security teams should also prioritize patching and mitigation efforts to prevent exploitation of this vulnerability in their environments, considering the potential impact on their security posture and the sensitivity of the data that could be accessed by exploiting this vulnerability.

Vendor
Elastic
Product
Kibana
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-02
Advisory published
2026-08-13
Advisory updated
2026-09-02

Who should care

Elastic Kibana administrators and users, security teams monitoring for potential unauthorized access to alerting rule execution telemetry, and operators responsible for maintaining Kibana spaces and access controls should be aware of this vulnerability. They should review and update Kibana configurations to restrict access and implement additional monitoring to detect and respond to potential unauthorized access attempts. Vulnerability management and security teams should also prioritize patching and mitigation efforts to prevent exploitation of this vulnerability in their environments, considering the potential impact on their security posture and the sensitivity of the data that could be accessed by exploiting this vulnerability. This includes ensuring that Kibana spaces are properly configured to enforce access controls and that users are aware of the potential risks associated with this vulnerability. Furthermore, asset inventory management and change management processes should be reviewed to ensure that affected systems are identified and prioritized for remediation. Monitoring and detection capabilities should also be evaluated to ensure they can detect potential exploitation attempts and unauthorized access to alerting rule execution telemetry. By taking these steps, organizations can reduce the risk associated with this vulnerability and protect their Kibana deployments from potential exploitation. Additionally, it is crucial for security teams to stay informed about the latest developments regarding this vulnerability and to be prepared to respond quickly in case of an attack. This involves staying up-to-date with vendor advisories, security bulletins, and other relevant information sources to ensure that they have the necessary knowledge and resources to effectively manage the risks associated with this vulnerability. Effective communication and collaboration between security teams, IT operations, and other stakeholders are also essential to ensure a coordinated and efficient response to this vulnerability. By prioritizing awareness, preparedness, and proactive security measures, organizations can minimize the potential impact of this vulnerability on

Technical summary

CVE-2026-72650 is an authorization bypass vulnerability in Kibana that allows an authenticated user, authorized to read alerting rules in one space, to retrieve execution telemetry of alerting rules from spaces they are not authorized to access. The disclosed telemetry includes rule identifiers, names, space identifiers, execution outcomes, timestamps, and counters. This vulnerability can be mitigated by restricting access to alerting rule execution telemetry based on user authorization and implementing additional monitoring.

Defensive priority

Authenticated users with limited authorization could potentially access sensitive alerting rule execution telemetry across different Kibana spaces.

Recommended defensive actions

  • Review and update Kibana configurations to restrict access to alerting rule execution telemetry based on user authorization.
  • Implement additional monitoring to detect and respond to potential unauthorized access attempts.
  • Ensure Kibana spaces are properly configured to enforce access controls.
  • Verify Kibana configurations and check for unauthorized access attempts.
  • Review user authorization and monitor for suspicious activity.
  • Conduct asset inventory management and change management processes to identify and prioritize affected systems for remediation.
  • Stay informed about the latest developments regarding this vulnerability and be prepared to respond quickly in case of an attack.

Evidence notes

The CVE-2026-72650 record indicates an authorization bypass vulnerability in Kibana, allowing authenticated users to access alerting rule execution telemetry across spaces they are not authorized for. Evidence is based on official CVE and NVD records. To verify, defenders should review Kibana configurations, check for unauthorized access attempts, and ensure proper space configuration. Additional verification steps include reviewing user authorization and monitoring for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72650 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72650

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72650 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72650

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-105/389521

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.