Kibana 8.19.22, 9.4.6 Security Update (ESA-2026-103)

Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read, modify, and delete draft Timeline objects belonging to other users in the same space. Read access is sufficient for enumeration and disclosure; the Timeline write privilege is required for modification and deletion.

Affected Versions:

  • 8.x: All versions from 8.0.0 up to and including 8.19.21
  • 9.x: All versions from 9.4.0 up to and including 9.4.5

Affected Configurations:
Kibana deployments that use the Security Solution Timeline feature.

Solutions and Mitigations:

The issue is resolved in Kibana version 8.19.22, 9.4.6.

For Users that Cannot Upgrade:

There are no workarounds

Indicators of Compromise (IOC)

A draft Timeline object whose creating user and last-updating user are distinct accounts indicates that a user other than the owner changed the object.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVE ID: CVE-2026-72662
Problem Type: CWE-639 - Authorization Bypass Through User-Controlled Key
Impact: CAPEC-1 - Accessing Functionality Not Properly Constrained by ACLs