Executive brief
Kibana is a data visualization and analysis tool used to search and explore data stored in Elasticsearch. An authenticated user with read-only access to security features can inappropriately modify Entity Store maintenance tasks, potentially disabling Entity Analytics functionality in their workspace and affecting data integrity.
Technical details
This is an authorization bypass vulnerability (CWE-863) in Kibana's Entity Store functionality, which was introduced in the 9.4 release line. A user holding only Security Solution read-level permissions can enumerate and change the state of Entity Store maintainer tasks, bypassing access control list (ACL) restrictions. The vulnerability requires authentication and network access to a Kibana instance, but involves no user interaction. An attacker can silently disable Entity Analytics maintenance for an entire Kibana space, affecting data consistency. The issue is resolved in Kibana 9.4.6 and 9.5.1; version 8.x and earlier are unaffected as Entity Store functionality was not present.
Affected products
- Elastic Kibana 9.4.0 through 9.4.5, 9.5.0
Timeline
- 2026-09-01: disclosed: Security advisory ESA-2026-122 published
- 2026-09-01: patched: Fixed in Kibana 9.4.6 and 9.5.1