CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-26939
Severity
MEDIUM
CVSS
6.5
EPSS
0.19%
Original NVD Description
Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). This requires an authenticated attacker with rule management privileges.
Related CVEs
Other vulnerabilities affecting the same vendor(s)