Description
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.
Published: 2026-09-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Loss of security monitoring due to privilege monitoring disabled
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an incorrect authorization flaw that allows an authenticated user with only read‑level Security feature access in Kibana to stop the recurring Privilege Monitoring engine task for a space. When the engine task is disabled, no monitoring data is produced for that space, yet the engine continues to report a healthy state to operators. The result is a loss of visibility into privileged user activity, giving an attacker or insider a blind spot in which illicit actions may go undetected.

Affected Systems

The issue affects Elastic’s Kibana product. No specific affected version numbers are provided in the available data, so any deployment running the vulnerable component should be presumed at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attack requires an authenticated user within the Kibana environment with read‑level Security feature permissions but no Elasticsearch privileges. The attacker could use the legitimate UI to disable the monitoring engine; thus the attack vector is internal, relying on legitimate credentials. Once disabled, the engine reports a false healthy status, masking the loss of monitoring for operators.

Generated by OpenCVE AI on September 2, 2026 at 01:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to the latest release that includes the fix for the privilege monitoring disabling issue.
  • Restrict read‑level Security feature users from accessing or modifying the Privilege Monitoring engine controls, ensuring only authorized personnel can disable the task.
  • Configure alerts or automated checks for the status of the Privilege Monitoring engine task so operators are notified promptly if it stops running.

Generated by OpenCVE AI on September 2, 2026 at 01:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Wed, 02 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.
Title Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitoring
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:42:19.825Z

Reserved: 2026-08-10T11:17:29.887Z

Link: CVE-2026-72633

cve-icon Vulnrichment

Updated: 2026-09-01T19:42:17.180Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:16.497

Modified: 2026-09-04T20:02:43.047

Link: CVE-2026-72633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T01:45:05Z

Weaknesses