漏洞概述 漏洞名称: Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private Locations CVE ID: CVE-2026-72673 CVSSv3.1: Medium (5.4) 问题类型: CWE-863 - Incorrect Authorization 影响: CAPEC-1 - Accessing Functionality Not Properly Constrained by ACLs 影响范围 受影响版本: - 8.x: 所有版本至8.19.19(包括8.19.19) - 9.x: 所有版本从9.0.0至9.4.3(包括9.4.3) 受影响配置: - 使用Synthetics并跨多个空间共享私有位置的Kibana部署 - 至少有一个用户仅在部分空间中拥有Synthetics写入权限 - 单空间部署不受影响,因为没有跨空间边界可绕过 - 自托管和Elastic Cloud托管部署均受影响 - 无需非默认配置 修复方案 解决方案: - 升级到8.19.20或9.4.4版本 对于无法升级的用户: - 不要跨多个空间共享Synthetics私有位置 - 仅授予信任的用户Synthetics写入权限,这些用户应有权访问使用该私有位置的所有空间 其他信息 相关主题: - Kibana 8.12.1 Security Update (ESA-2024-21) - Kibana 8.19.20, and 9.4.5 Security Update (ESA-2026-92) - Kibana 8.19.14, 9.2.8, 9.3.3 Security Update (ESA-2026-25) - Kibana 9.4.4 Security Update (ESA-2026-73) - Kibana 8.19.20 and 9.4.5 Security Update (ESA-2026-88) 代码块 页面中未包含POC代码或利用代码。