Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic kibana |
|
| Vendors & Products |
Elastic
Elastic kibana |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space. | |
| Title | Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-01T19:42:33.075Z
Reserved: 2026-08-10T11:17:35.480Z
Link: CVE-2026-72641
Updated: 2026-09-01T19:42:30.336Z
Status : Awaiting Analysis
Published: 2026-09-01T20:17:16.613
Modified: 2026-09-01T21:15:37.123
Link: CVE-2026-72641
No data.
OpenCVE Enrichment
Updated: 2026-09-02T04:00:08Z
-
CWE-863
Incorrect Authorization