CVE-2026-72641

MEDIUM CVSS 3.1: 5.4 EPSS 0.22%
Updated Sep 02, 2026
Kibana
Parameter Value
CVSS 5.4 (MEDIUM)
Affected Versions 9.4.0 — 9.4.6
Fixed In 9.4.6
Type CWE-863 (Incorrect Authorization)
Vendor Kibana
Public PoC No

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
9.4.0 9.4.6
Elastic Kibana
cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*