CVE-2026-56146
Received Received - Intake

Improper Access Control in Kibana Entity Analytics

Vulnerability report for CVE-2026-56146, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Elastic

Description

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
elastic kibana *
elastic kibana From 9.4.0 (inc) to 9.4.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Access Control issue in Kibana, where a low-privileged authenticated user with read-only Security Solution access can perform write operations on Entity Analytics Watchlist configuration. This violates the intended access control policies and could lead to unauthorized modifications or information disclosure.

Detection Guidance

To detect this vulnerability, check if your Kibana instance is running a vulnerable version (9.4.0 to 9.4.2). Verify the version using the command: curl -X GET "http://localhost:5601/api/console/proxy?path=%2Fapi%2Fstatus&method=GET". If the version is below 9.4.3, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability could allow an attacker to modify watchlist data they should not have access to, potentially altering security configurations. In specific deployment scenarios, it might also enable unauthorized access to sensitive data beyond their permitted scope.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Unauthorized changes to security configurations or data exposure could result in legal penalties or loss of certification.

Mitigation Strategies

Update Kibana to the latest patched version immediately to address the improper access control vulnerability. Review and restrict user permissions to ensure low-privileged users cannot perform write operations on watchlist data. Monitor logs for unauthorized modification attempts to Entity Analytics Watchlist configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56146. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart