Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-58/388557 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-21 20:17
Updated : 2026-08-06 13:02
NVD link : CVE-2026-56146
Mitre link : CVE-2026-56146
CVE.ORG link : CVE-2026-56146
JSON object : View
Products Affected
elastic
- kibana
CWE
CWE-863
Incorrect Authorization
