HIGHVulnerability

CVE-2026-72658

Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.

Properties

severity
HIGH
score
7.3
epss_score
0.00133
cve_id
CVE-2026-72658
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
published_at
2026-08-13T20:17:26.017
last_modified
2026-09-02T14:18:12.247
epss_percentile
0.0314

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Cross-Site Request Forgery (CSRF)

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72658 — Ninja Signal Threat Intelligence | Ninja Signal