Incorrect Authorization in Kibana Entity Analytics by Elastic
CVE-2026-72633

4.3MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-72633?

An authorization flaw in Kibana Entity Analytics allows an authenticated user, with only read-level access to security features and without Elasticsearch privileges, to disable the Privilege Monitoring engine task for a specific Kibana space. This manipulation halts the generation of monitoring data while misleading operators by displaying a healthy status, ultimately undermining the integrity of security monitoring within the environment.

Affected Version(s)

Kibana 9.1.0 <= 9.4.5

Kibana 9.5.0 <= 9.5.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.