Incorrect authorization in Kibana - CVE-2026-72641
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to modify data.
The vulnerability exists due to incorrect authorization in Entity Store maintainer tasks when accessing functionality not properly constrained by ACLs. A remote user can enumerate and change the state of maintainer tasks to modify data.
Only users with Security Solution read access in a Kibana space can exploit the issue, which can silently disable Entity Analytics maintenance for that space.