Medium severity5.4NVD Advisory· Published Jul 21, 2026· Updated Aug 6, 2026
CVE-2026-56146
CVE-2026-56146
Description
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versions
>= 9.4.0, < 9.4.3+ 1 more
- (no CPE)range: >= 9.4.0, < 9.4.3
- (no CPE)range: >= 9.4.0, < 9.4.3
Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-58/388557nvdVendor Advisory
News mentions
0No linked articles in our index yet.