Description
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.
Published: 2026-09-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of data
Action: Immediate Patch
AI Analysis

Impact

A flaw in the authorization logic of Kibana allows an authenticated user with only read‑only access within a Kibana space to discover and alter entity store maintainer tasks. By toggling these tasks the user can silently disable the automated Entity Analytics maintenance, leading to loss of data analysis capabilities and potential data inconsistencies without the data owners’ knowledge. The weakness is a classic authorization bypass (CWE‑863).

Affected Systems

The vulnerability affects Elastic’s Kibana product. Users running any version of Kibana that has not been hardened to this update are potentially impacted; the advisory at the provided link confirms that the issue existed in releases prior to the listed security update.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently known to be actively exploited in the wild. The attack requires a valid account with read access in a Kibana space; it can be performed without additional network-level privileges, making the exploit relatively straightforward for anyone who has legitimate Kibana credentials. Because the effect is the inadvertent disabling of analytics maintenance, the impact is primarily a loss of functional integrity rather than a direct confidentiality or availability breach. The lack of a publicly available exploit does not eliminate the risk, however; an attacker controlling a read‑only user could mount automated scans to find vulnerable spaces and modify resources as described.

Generated by OpenCVE AI on September 2, 2026 at 02:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to the latest patched version that addresses this issue
  • Restrict read‑only users from modifying entity store maintainer tasks or adjust ACLs to deny modification capabilities
  • Enable Kibana’s audit logging for space-level modifications to detect and investigate unauthorized changes to entity store maintainer tasks

Generated by OpenCVE AI on September 2, 2026 at 02:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*

Wed, 02 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.
Title Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:42:33.075Z

Reserved: 2026-08-10T11:17:35.480Z

Link: CVE-2026-72641

cve-icon Vulnrichment

Updated: 2026-09-01T19:42:30.336Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:16.613

Modified: 2026-09-02T14:21:12.850

Link: CVE-2026-72641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:00:08Z

Weaknesses