CVE-2026-72641: Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
An authenticated user who has only Security Solution read access in a Kibana space can exploit the issue. The impact is limited to Entity Store maintainer tasks for that space.
What can an attacker change?
The attacker can enumerate Entity Store maintainer tasks and change their state. This can silently disable Entity Analytics maintenance in the affected Kibana space.
Is user interaction required?
No. The vulnerability is exploitable by a low-privileged authenticated user without user interaction.