PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72658 Elastic CVE debrief

A Cross-Site Request Forgery (CWE-352) vulnerability exists in Kibana, which can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user permitted to create visualizations can save a specially crafted Vega visualization. When opened by another user, it causes authenticated requests to be issued to Kibana in the context of the viewing user's session. The vulnerability has a CVSS score of 7.3 and is considered high severity. Organizations using Kibana should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-13T20:17:26.017Z and has not been modified since then. Kibana users with visualization creation permissions are at risk of exploitation. To address this vulnerability, users should apply patches or updates provided by Elastic. Additionally, restricting permissions for creating visualizations to trusted users and monitoring Kibana logs for suspicious activity can help prevent potential attacks.

Vendor
Elastic
Product
Kibana
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-02
Advisory published
2026-08-13
Advisory updated
2026-09-02

Who should care

Organizations using Kibana, especially those with users who have permission to create visualizations, should be aware of this vulnerability and take steps to mitigate it. This includes applying patches or updates provided by Elastic, restricting permissions for creating visualizations to trusted users, and monitoring Kibana logs for suspicious activity. Security teams and operators managing Kibana deployments should prioritize patching to prevent potential privilege escalation attacks. Implementing additional security measures, such as Web Application Firewalls (WAFs), can also help detect and prevent CSRF attacks. Affected organizations should review their current Kibana usage and assess the potential impact of this vulnerability on their systems and data. They should also ensure that their incident response plans are updated to address potential exploitation of this vulnerability. Furthermore, organizations should verify that their Kibana instances are up-to-date and that all necessary security patches have been applied. Regular security audits and vulnerability assessments can help identify potential weaknesses in Kibana deployments. By taking these steps, organizations can reduce the risk of exploitation and protect their systems and data from potential attacks. Kibana administrators should also consider implementing compensating controls, such as IP blocking or rate limiting, to further mitigate the risk of exploitation. Effective communication and coordination between security teams, operators, and other stakeholders are crucial to ensuring the timely and effective mitigation of this vulnerability. Finally, organizations should document their mitigation efforts and maintain records of their Kibana deployment and security configurations to facilitate future vulnerability management and incident response activities. This documentation can also help organizations demonstrate compliance with relevant security policies and regulations. By prioritizing the mitigation of this vulnerability and maintaining a proactive approach to security, organizations can minimize the risk of exploitation and protect their Kibana deployments from potential attacks. In addition,

Technical summary

A Cross-Site Request Forgery (CWE-352) vulnerability exists in Kibana, which can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user permitted to create visualizations can save a specially crafted Vega visualization. When opened by another user, it causes authenticated requests to be issued to Kibana in the context of the viewing user's session. The vulnerability has a CVSS score of 7.3 and is considered high severity.

Defensive priority

Organizations using Kibana should prioritize patching to prevent potential privilege escalation attacks.

Recommended defensive actions

  • Apply patches or updates provided by Elastic to address the vulnerability in Kibana.
  • Restrict permissions for creating visualizations to trusted users.
  • Monitor Kibana logs for suspicious activity.
  • Implement additional security measures, such as Web Application Firewalls (WAFs), to detect and prevent CSRF attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE-2026-72658 record indicates a Cross-Site Request Forgery (CWE-352) vulnerability in Kibana, which can lead to privilege escalation. A user with visualization creation permissions can craft a malicious Vega visualization that, when opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session. The CVSS score is 7.3, indicating a high severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72658 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72658

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72658 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72658

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-99/389529

    [email protected] - Vendor Advisory, Mitigation

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.