Subscriptions
No data.
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 19 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). This requires an authenticated attacker with rule management privileges. | |
| Title | Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configuration | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-03-19T17:50:30.754Z
Reserved: 2026-02-16T16:42:05.774Z
Link: CVE-2026-26939
Updated: 2026-03-19T17:50:23.146Z
Status : Received
Published: 2026-03-19T18:16:21.690
Modified: 2026-03-19T18:16:21.690
Link: CVE-2026-26939
No data.
OpenCVE Enrichment
No data.