{ "canonical_id": "kibana--012933e759", "system_id": "kibana", "display_name": "Kibana", "category": "platforms", "advisory_mode": "core", "title": "Kibana 8.19.12, 9.2.6, 9.3.1 Security Update (ESA-2026-19)", "summary": "
Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configuration
\nMissing Authorization (CWE-862) in Kibana\u2019s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). This requires an authenticated attacker with rule management privileges.
\nAffected Versions:
\nAffected Configurations:
\nSolutions and Mitigations:
\nThe issue is resolved in version 8.19.12, 9.2.6, 9.3.1.
\nFor Users that Cannot Upgrade:
\nUpdate to the patched version as soon as possible. In the interim, restrict detection rule management privileges to users who are also authorized for endpoint response actions. Review existing rules for any unauthorized response action configurations that may have been added.
\nIndicators of Compromise (IOC)
\nAudit all detection rules for response_actions configurations containing .endpoint action types (isolate, kill-process, suspend-process) that may have been added by unauthorized users.
Elastic Cloud Serverless
\nDue to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.
\nSeverity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
\nCVE ID: CVE-2026-26939
\nProblem Type: CWE-862 - Missing Authorization
\nImpact: Accessing Functionality Not Properly Constrained by ACLs - CAPEC-1
1 post - 1 participant
\n ", "published_at": "Thu, 19 Mar 2026 16:51:08 +0000", "updated_at": "Thu, 19 Mar 2026 16:51:08 +0000", "severity": "unknown", "cvss_score": null, "exploit_status": "unknown", "source_confidence": "official", "official_source_url": "https://discuss.elastic.co/t/kibana-8-19-12-9-2-6-9-3-1-security-update-esa-2026-19/385530", "secondary_source_urls": [], "aliases": [], "cve_ids": [], "ghsa_ids": [], "osv_ids": [], "affected_versions": [], "fixed_versions": [], "package_name": null, "render_markdown": false, "case_path": null, "secure_code_topics": [ "authz-server-side-recheck", "xss-output-encoding", "proxy-trust-boundary", "dependency-upgrade-policy" ], "status": "triage", "triage_reasons": [ "missing affected/fixed version details" ], "verification_status": "triage-manual", "verification_mode": "synthetic", "last_verified_at": null, "last_run_id": null, "evidence_bundle": null, "historical_status": null, "latest_status": null, "browser_evidence": { "required": false, "present": false, "refs": [] }, "repro_profile_id": "xss-generic", "artifact_mode": "synthetic", "blocked_reason": null, "metadata": { "source_names": [ "Elastic Security Announcements RSS" ], "source_kinds": [ "rss-feed" ], "candidate_count": 1 } }