CVE-2026-72658

HIGH CVSS 3.1: 7.3 EPSS 0.13%
Updated Aug 14, 2026
Kibana
Parameter Value
CVSS 7.3 (HIGH)
Type CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor Kibana
Public PoC No

Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1