{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72658","assignerOrgId":"271b6943-45a9-4f3a-ab4e-976f3fa05b5a","state":"PUBLISHED","assignerShortName":"elastic","dateReserved":"2026-08-10T11:17:45.102Z","datePublished":"2026-08-13T19:12:48.248Z","dateUpdated":"2026-08-14T03:56:08.941Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Kibana","vendor":"Elastic","versions":[{"status":"affected","versionType":"semver","version":"8.19.0","lessThanOrEqual":"8.19.19"},{"status":"affected","versionType":"semver","version":"9.0.0","lessThanOrEqual":"9.4.4"}]}],"descriptions":[{"lang":"en","value":"Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.</p>"}]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-352","description":"CWE-352 Cross-Site Request Forgery","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"271b6943-45a9-4f3a-ab4e-976f3fa05b5a","shortName":"elastic","dateUpdated":"2026-08-13T19:12:48.248Z"},"references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-20-and-9-4-5-security-update-esa-2026-99/389529"}],"source":{"discovery":"Elastic"},"title":"Cross-Site Request Forgery in Kibana Leading to Privilege Escalation","x_generator":{"engine":"Elastic CVE Publisher 1.0.0"},"impacts":[{"capecId":"CAPEC-62","descriptions":[{"lang":"en","value":"CAPEC-62 Cross Site Request Forgery"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-13T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-72658"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-14T03:56:08.941Z"}}]}}