{"id":"CVE-2026-72641","summary":"Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data","details":"Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.","modified":"2026-09-05T03:49:18.822715347Z","published":"2026-09-01T19:20:23.368Z","database_specific":{"cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72641.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"9.4.0"},{"last_affected":"9.4.5"},{"introduced":"9.5.0"},{"last_affected":"9.5.0"}]}],"cna_assigner":"elastic"},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-9-4-6-9-5-1-security-update-esa-2026-122/390089"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72641.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72641"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"2e8528e92361c3399724226deaf2b46f933e925b"},{"fixed":"10011cbc74640115d0ffac0cef7c925aec4754f5"},{"introduced":"8d4246a64bc255212407b1b313fe402391299c88"},{"last_affected":"8d4246a64bc255212407b1b313fe402391299c88"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.4.0"},{"fixed":"9.4.6"},{"introduced":"9.5.0"},{"last_affected":"9.5.0"}]}}],"versions":["9.5.0","v9.4.5","v9.5.0","v9.4.4","v9.4.3","v9.4.2","v9.4.1","v9.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72641.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"b2e39752e03b56f48f51943214475ddba1f8e974"},{"fixed":"692551ad493ed71169e295e2160446428ee00b15"},{"introduced":"240f7d17d21408117f4295bcf74d48092ab0d078"},{"last_affected":"240f7d17d21408117f4295bcf74d48092ab0d078"}],"database_specific":{"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.4.0"},{"fixed":"9.4.6"},{"introduced":"9.5.0"},{"last_affected":"9.5.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.5.0","v9.4.5","v9.5.0","v9.4.4","v9.4.3","v9.4.2","v9.4.1","v9.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72641.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"}]}