Junglewise Threat Intelligence

CVE-2026-72633: Elastic Kibana authorization bypass in Entity Analytics

CVE-2026-72633 · Severity: medium · CVSS 4.3 · Published 2026-09-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana Entity Analytics, a security monitoring engine in Elastic's Kibana platform, contains an authorization flaw that allows read-only security users to disable privileged user monitoring. An attacker with basic read-level access can stop the privilege monitoring engine, causing it to halt data collection while falsely reporting healthy status to administrators. This breaks critical security visibility, potentially allowing malicious privilege escalations or unauthorized account activity to go undetected.

Technical details

A CWE-863 incorrect authorization vulnerability exists in Kibana Entity Analytics' privilege monitoring engine. An authenticated user holding only read-level Security feature access (no Elasticsearch admin privileges required) can stop the recurring privilege monitoring task for a Kibana space via an improperly constrained ACL. The vulnerability allows attackers to disable the engine while it continues to report success to operators, creating a false sense of security. The flaw affects Kibana 9.x versions 9.1.0 through 9.4.5 and 9.5.0 through 9.5.1; it is resolved in versions 9.4.6 and 9.5.2. Exploitation requires an authenticated Kibana account and a Kibana deployment where Entity Analytics has been initialized.

Affected products

  • Elastic Kibana 9.1.0 through 9.4.5, 9.5.0 through 9.5.1

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in Kibana 9.4.6 and 9.5.2

References

Related threats