🚨 CVE-2026-72641
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.
🎖@cveNotify
Discuss the Elastic Stack
Kibana 9.4.6, 9.5.1 Security Update (ESA-2026-122)
Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated…

September 2, 2026 20