{"id":"CVE-2026-26939","summary":"Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configuration","details":"Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). This requires an authenticated attacker with rule management privileges.","modified":"2026-07-22T03:08:48.008798Z","published":"2026-03-19T17:11:16.507Z","database_specific":{"cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26939.json","unresolved_ranges":[{"extracted_events":[{"introduced":"9.0.0"},{"last_affected":"9.2.5"},{"introduced":"9.3.0"},{"last_affected":"9.3.0"},{"introduced":"8.0.0"},{"last_affected":"8.19.11"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"elastic"},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-8-19-12-9-2-6-9-3-1-security-update-esa-2026-19/385530"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26939.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26939"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"840cd2a58b052d1632219ee0b8dcc0f364226287"},{"introduced":"112859b85d50de2a7e63f73c8fc70b99eea24291"},{"fixed":"b6e59ddaac5fc0c537d10132b2a1d5511ff8b1b5"},{"introduced":"17b451d8979a29e31935fe1eb901310350b30e62"},{"last_affected":"17b451d8979a29e31935fe1eb901310350b30e62"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.19.12"},{"introduced":"9.0.0"},{"fixed":"9.2.6"},{"introduced":"9.3.0"},{"last_affected":"9.3.0"}]}}],"versions":["9.3.0","v9.3.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"9475014608979432872899083491102618214","length":1769},"id":"CVE-2026-26939-23fdb02b","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/b6e59ddaac5fc0c537d10132b2a1d5511ff8b1b5","target":{"file":"x-pack/plugin/async-search/src/internalClusterTest/java/org/elasticsearch/xpack/search/CrossClusterAsyncSearchIT.java","function":"setupTwoClusters"}},{"deprecated":false,"digest":{"function_hash":"133451266018049555307972036747567205009","length":958},"id":"CVE-2026-26939-44709111","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287","target":{"file":"x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java","function":"syncBuiltInRoles"}},{"deprecated":false,"digest":{"line_hashes":["99199954569926070389755590458431893865","313759815407396439660281880388391585122","161102645631341755952971719744845873602","4186666920153198943865131845554032355","25468090382942619615217774101002806341","313470468710636859297439073751114276151","66718931484630687447592857125186493460","24207978016146776076969048411650729239","112550863571627868281286215194724888191","257629881162110032714395006537365108931"],"threshold":0.9},"id":"CVE-2026-26939-5f9a6220","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287","target":{"file":"x-pack/plugin/security/src/test/java/org/elasticsearch/test/SecurityIntegTestCase.java"}},{"id":"CVE-2026-26939-7eb3b816","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287","target":{"function":"isSynchronizationInProgress","file":"x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java"},"deprecated":false,"digest":{"length":72,"function_hash":"101359613813715596799098669389468934232"}},{"deprecated":false,"digest":{"line_hashes":["290299200757894439583714815578812186718","169655607745751903048488107101990058530","166338349120674636449812377777594551776"],"threshold":0.9},"id":"CVE-2026-26939-8105e18c","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287","target":{"file":"x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizerTests.java"}},{"source":"https://github.com/elastic/elasticsearch/commit/b6e59ddaac5fc0c537d10132b2a1d5511ff8b1b5","target":{"file":"x-pack/plugin/async-search/src/internalClusterTest/java/org/elasticsearch/xpack/search/CrossClusterAsyncSearchIT.java"},"deprecated":false,"digest":{"line_hashes":["90084914409573906936379757312165312850","121001556755942392594861396647986502913","292860262293276780122791861456517913809","189064083144340558976097844419482161337","170036109944766967794168654275475188267","168830856035572788271810376702342495","7330473078786494025208501359190291269","305654221205411734981376222466159728667","173345538729514816951386971234382160660","10277180135323892648044603022783539034","93032768154059099699148095793739178027","179625484193996379183604122731081889294","132776780032578476164481467186876729006","96140669458429765970392877159221345914","174007588216295496161116936143898622479"],"threshold":0.9},"id":"CVE-2026-26939-b1b96921","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287","target":{"file":"x-pack/plugin/security/src/test/java/org/elasticsearch/test/SecurityIntegTestCase.java","function":"createSecurityIndexWithWaitForActiveShards"},"deprecated":false,"digest":{"function_hash":"295080310505497328800607122027489892634","length":583},"id":"CVE-2026-26939-c550a0a2"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287","target":{"file":"x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java"},"deprecated":false,"digest":{"line_hashes":["32062625129072983920028058538884317534","36605260437218003236676516717207376115","275251572708192921560642949692454487127","69322198935595094552544202420825303013","204189508549580167203700003970685711717","200275780857157123884837014463936936819","200238213166771762231720223821092393486","77080184640576469221069162275208661231","241552448252549514344260546419342732416","184395862190808686364654112287864626160","21262340089191862322692044690513150724","303168300053863300365532002986515824616","244043743419304174755717618883052239773","198601726773172707137865878432157927310","160173067990907518481820168210750268959","118536611432114572498533366946624056113","151188083657138064173439508561926804321","66303635313521987898486263919309796562","57127652560644982036908021870230098795","169729806556418315554213555995148801320","141277772941142071605729341553562846393","215408178278593721394502038286795177004","108358083274527797828220886478330682407","135995618942555241468159231912235903527","203013557821300387940709907789468421849","80140506738272190341199483727436797382","317723253769294839897187586336466383329","280291953243866521885009154568627033710","59988699721419414186936302902640832220","49607341567707384950739807477900815537","146678715625423207459312251605852192704","261672105894779227279495728143227053252","2057074736663939076853955293574438681","105131071792840334483021920478890716067","276622381611640845305936267226422248145","335070780292288339104560083098573027458","79046161274681637502415961148099472733","245256323743556361925328426612049245288","106491649802133929311570607434105379098","31826412590017207828168230672741708725","235850409320295939375720298931624755438"],"threshold":0.9},"id":"CVE-2026-26939-dca7c99a"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26939.json","vanir_signatures_modified":"2026-07-22T03:08:48Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"57ca5e139a33dd2eed927ce98d8231a1f217cd15"},{"fixed":"a2a93735478172a315d2ced4aded3024cc029648"},{"introduced":"504d6bfa94cca17fabb76e06152c30c4f0c3efdd"},{"fixed":"3223f0953e9361aa0317520c49c8b4c3796cc4c3"},{"introduced":"30ab63cc0017fe2da7a84fb9b285dd762468802d"},{"last_affected":"30ab63cc0017fe2da7a84fb9b285dd762468802d"}],"database_specific":{"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.19.12"},{"introduced":"9.0.0"},{"fixed":"9.2.6"},{"introduced":"9.3.0"},{"last_affected":"9.3.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.3.0","v9.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26939.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}