CVE-2026-72658 | Elastic Kibana up to 8.19.19/9.4.4 Vega cross-site request forgery

SecurityVulns

A vulnerability described as problematic has been identified in Elastic Kibana up to 8.19.19/9.4.4. This issue affects some unknown processing of the component Vega Handler. Executing a manipulation can lead to cross-site request forgery.

This vulnerability is registered as CVE-2026-72658. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More