Incorrect authorization in Kibana - CVE-2026-72633
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disable privilege monitoring for a Kibana space.
The vulnerability exists due to incorrect authorization in Kibana Entity Analytics when handling requests to stop the recurring Privilege Monitoring engine task. A remote user can send a request to stop the task to disable privilege monitoring for a Kibana space.
Exploitation requires read-level Security feature access in the target space, and the Entity Analytics Privilege Monitoring engine must have been initialized.