Missing Authorization in Kibana Leads to Unauthorized Actions
CVE-2026-26939
6.5MEDIUM
What is CVE-2026-26939?
The vulnerability in Kibana's server-side Detection Rule Management system allows authenticated attackers with rule management privileges to configure unauthorized endpoint response actions. This includes critical functionalities such as host isolation, process termination, and process suspension, all of which can be performed without proper access controls, exposing systems to potential exploitation.
Affected Version(s)
Kibana 9.0.0 <= 9.2.5
Kibana 9.3.0
Kibana 8.0.0 <= 8.19.11