Junglewise Threat Intelligence

CVE-2026-72641: Elastic Kibana authorization bypass in Entity Store maintenance

CVE-2026-72641 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and analysis tool used to search and explore data stored in Elasticsearch. An authenticated user with read-only access to security features can inappropriately modify Entity Store maintenance tasks, potentially disabling Entity Analytics functionality in their workspace and affecting data integrity.

Technical details

This is an authorization bypass vulnerability (CWE-863) in Kibana's Entity Store functionality, which was introduced in the 9.4 release line. A user holding only Security Solution read-level permissions can enumerate and change the state of Entity Store maintainer tasks, bypassing access control list (ACL) restrictions. The vulnerability requires authentication and network access to a Kibana instance, but involves no user interaction. An attacker can silently disable Entity Analytics maintenance for an entire Kibana space, affecting data consistency. The issue is resolved in Kibana 9.4.6 and 9.5.1; version 8.x and earlier are unaffected as Entity Store functionality was not present.

Affected products

  • Elastic Kibana 9.4.0 through 9.4.5, 9.5.0

Timeline

  • 2026-09-01: disclosed: Security advisory ESA-2026-122 published
  • 2026-09-01: patched: Fixed in Kibana 9.4.6 and 9.5.1

References

Related threats