Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-72669

7 дней назад

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover the onboarding flows of other users, read their onboarding state, and write arbitrary progress data into them. A tampered flow can also cause the owner's onboarding view to fail with a server error.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2026-72669

7 дней назад

The state that Kibana stores for an Observability Onboarding flow is n ...

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3f72-7fqv-qch8

7 дней назад

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover the onboarding flows of other users, read their onboarding state, and write arbitrary progress data into them. A tampered flow can also cause the owner's onboarding view to fail with a server error.

CVSS3: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-72669

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover the onboarding flows of other users, read their onboarding state, and write arbitrary progress data into them. A tampered flow can also cause the owner's onboarding view to fail with a server error.

CVSS3: 7.6
0%
Низкий
7 дней назад
debian логотип
CVE-2026-72669

The state that Kibana stores for an Observability Onboarding flow is n ...

CVSS3: 7.6
0%
Низкий
7 дней назад
github логотип
GHSA-3f72-7fqv-qch8

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover the onboarding flows of other users, read their onboarding state, and write arbitrary progress data into them. A tampered flow can also cause the owner's onboarding view to fail with a server error.

CVSS3: 7.6
0%
Низкий
7 дней назад

Уязвимостей на страницу