CVE-2026-72641 Incorrect Authorization (CWE-863) in Kibana can lead… — CVE Notify — TG.ME

🚨 CVE-2026-72641
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.

🎖@cveNotify
Discuss the Elastic Stack
Kibana 9.4.6, 9.5.1 Security Update (ESA-2026-122)
Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated…
September 2, 2026 20