Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic kibana |
|
| Vendors & Products |
Elastic
Elastic kibana |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators. | |
| Title | Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitoring | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-01T19:42:19.825Z
Reserved: 2026-08-10T11:17:29.887Z
Link: CVE-2026-72633
Updated: 2026-09-01T19:42:17.180Z
Status : Awaiting Analysis
Published: 2026-09-01T20:17:16.497
Modified: 2026-09-01T21:15:37.123
Link: CVE-2026-72633
No data.
OpenCVE Enrichment
Updated: 2026-09-02T01:45:05Z