SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72641

MEDIUM · CVSS 5.4 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kibana contains an incorrect authorization vulnerability that allows authenticated users with only read access to modify data by bypassing access control lists. This could result in unauthorized changes to the state of Entity Store maintainer tasks, potentially disabling critical maintenance functions for Entity Analytics. Organizations using Kibana, especially those implementing security solutions, should prioritize addressing this issue to prevent data integrity risks.

CVE
CVE-2026-72641
Severity
MEDIUM
CVSS
5.4
EPSS
0.22%

Original NVD Description

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.

Related CVEs

Other vulnerabilities affecting the same vendor(s)