PT-2026-84385 · Elastic · Kibana

CVE-2026-72633

·

Published

2026-09-01

·

Updated

2026-09-07

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description Incorrect authorization in Kibana Entity Analytics allows an authenticated user with only read-level Security feature access and no Elasticsearch privileges to stop the recurring Privilege Monitoring engine task for a Kibana space. This results in a loss of security monitoring as privileged user monitoring stops producing data for that space, even though the engine continues to report a healthy state to operators.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-72633
BIT-KIBANA-2026-72633
CVE-2026-72633

Affected Products

Kibana