A vulnerability described as problematic has been identified in Elastic Kibana up to 8.19.19/9.4.4. This issue affects some unknown processing of the component Vega Handler. Executing a manipulation can lead to cross-site request forgery.

This vulnerability is registered as CVE-2026-72658. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.