CVE-2026-72633
Last modified
CVE-2026-72633 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 9.1.0, < 9.4.6 |
| Elastic | Kibana | >= 9.5.0, < 9.5.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-72633?
How severe is CVE-2026-72633?
How do I fix CVE-2026-72633?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72628Improper Handling of Highly Compressed Data (CWE-409) in Kib…6.5
- CVE-2026-72629Authorization Bypass Through User-Controlled Key (CWE-639) i…7.1
- CVE-2026-7263In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, …7.5
- CVE-2026-72630Incorrect Authorization (CWE-863) in Kibana Fleet can lead t…7.1
- CVE-2026-72631Improper Privilege Management (CWE-269) in Kibana Fleet can …6.5
- CVE-2026-72632Observable Discrepancy (CWE-203) in Kibana Fleet can lead to…7.1
- CVE-2026-72636Uncontrolled Recursion (CWE-674) in the Elasticsearch wildca…6.5
- CVE-2026-72638Uncontrolled Recursion (CWE-674) in Elasticsearch can lead t…6.5
- CVE-2026-72639Elasticsearch does not enforce an upper bound on a user-supp…6.5
- CVE-2026-7264A weakness has been identified in SourceCodester Pizzafy Eco…6.3
- CVE-2026-72640The Elastic Cloud on Kubernetes (ECK) operator reads a list …6.5
- CVE-2026-72641Incorrect Authorization (CWE-863) in Kibana can lead to unau…5.4
Are you affected by CVE-2026-72633?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
