Unrated severityNVD Advisory· Published Mar 19, 2026· Updated Mar 19, 2026
Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configuration
CVE-2026-26939
Description
Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). This requires an authenticated attacker with rule management privileges.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.