SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72633

MEDIUM · CVSS 4.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kibana Entity Analytics is vulnerable due to incorrect authorization, allowing authenticated users with only read-level access to halt the Privilege Monitoring engine task for a specific Kibana space, despite lacking Elasticsearch privileges. This can lead to a significant loss of security monitoring capabilities, as the engine will falsely report a healthy state while failing to collect critical data. Organizations utilizing Kibana for security monitoring should prioritize addressing this vulnerability to maintain effective oversight and prevent potential security lapses.

CVE
CVE-2026-72633
Severity
MEDIUM
CVSS
4.3
EPSS
0.19%

Original NVD Description

Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.

Related CVEs

Other vulnerabilities affecting the same vendor(s)