Unrated severityNVD Advisory· Published Jul 21, 2026· Updated Jul 22, 2026
Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure
CVE-2026-56146
Description
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.
Affected products
3- osv-coords2 versions
>= 9.4.0, < 9.4.3+ 1 more
- (no CPE)range: >= 9.4.0, < 9.4.3
- (no CPE)range: >= 9.4.0, < 9.4.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.