CVE-2026-56146: Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to Kibana Security Solution watchlist/Entity Analytics watchlist configuration functions so that only elevated/admin users can perform write operations; ensure read-only Security Solution roles cannot modify watchlist data.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56146?
The severity of CVE-2026-56146 is rated as medium with a score of 5.4.
What does CVE-2026-56146 exploit?
CVE-2026-56146 exploits improper access control in Kibana, allowing unauthorized modification of watchlist configurations.
Who is affected by CVE-2026-56146?
Users of Elastic Kibana with low-privileged authenticated access could be affected by CVE-2026-56146.
How can I mitigate CVE-2026-56146?
To mitigate CVE-2026-56146, ensure that proper access controls and permissions are enforced on watchlist data.
What are the potential risks of CVE-2026-56146?
The potential risks of CVE-2026-56146 include unauthorized data modification and information disclosure.