Improper Access Control in Kibana by Elastic
CVE-2026-56146

5.4MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-56146?

An improper access control vulnerability in Kibana enables low-privileged users with read-only access to inadvertently perform unauthorized modifications on the Entity Analytics Watchlist configuration. This flaw could lead to information disclosure, as such users may execute write operations on data that should only be modifiable by users with elevated privileges. Under certain deployment scenarios, this vulnerability may also allow access to data that exceeds the user’s authorized permissions, potentially leading to further security issues.

Affected Version(s)

Kibana 9.4.0 <= 9.4.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.