Kibana 8.x < 8.19.20 / 9.x < 9.4.4 Incorrect Authorization (ESA-2026-90)

medium Nessus Plugin ID 338727

Synopsis

The remote host is affected by an incorrect authorization vulnerability.

Description

The version of Kibana installed on the remote host is 8.x prior to 8.19.20, or 9.x prior to 9.4.4. It is, therefore, affected by a vulnerability as referenced in the ESA-2026-90 advisory.

- Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it from every space it is shared with. The safeguard that prevented the deletion of a private location still in use evaluated only the monitors visible in the requesting user's own space, so monitors that depend on the private location in other spaces were not taken into account. As a result, an authenticated Kibana user holding the Synthetics write privilege in a single space could delete a private location that other spaces still depend on, even where the user has no access to those spaces. (CVE-2026-72673)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update to Kibana version 8.19.20, 9.4.4 or later.

See Also

http://www.nessus.org/u?559b7c63

Plugin Details

Severity: Medium

ID: 338727

File Name: kibana_esa_2026_90.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.92

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

CVSS Score Source: CVE-2026-72673

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Vulnerability Information

CPE: cpe:/a:elasticsearch:kibana

Required KB Items: installed_sw/Kibana

Patch Publication Date: 8/13/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-72673

CWE: 863

IAVB: 2026-B-0232