BIT-elk-2026-72650

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/elk/BIT-elk-2026-72650.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-elk-2026-72650
Aliases
Published
2026-08-19T08:40:24Z
Modified
2026-09-08T08:47:09Z
Summary
Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure
Details

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve alerting rule execution telemetry that belongs to spaces the user is not authorized to access. The disclosed telemetry includes rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters.

Database specific
{
    "cpes": [
        "cpe:2.3:a:elasticsearch:kibana:*:*:*:*:*:node.js:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / elk

Package

Name
elk
Purl
pkg:bitnami/elk

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.19.20
Introduced
9.0.0
Fixed
9.4.5

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/elk/BIT-elk-2026-72650.json"