CVE-2026-56147: Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity Compromise
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and delete case attachments that belong to feature areas they are not authorized to access. Because the access control check and the resource retrieval use different resolution mechanisms, an authenticated attacker with limited file management permissions can obtain the contents of, modify, or delete protected case attachments — such as those associated with Security Solution cases — without holding the privileges required to access those features.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56147?
The severity of CVE-2026-56147 is rated as high with a score of 7.1.
How do I fix CVE-2026-56147?
You can fix CVE-2026-56147 by updating to the latest version of Elastic Kibana that addresses the vulnerability.
What type of vulnerability is CVE-2026-56147?
CVE-2026-56147 is an authorization bypass vulnerability that allows unauthorized information disclosure.
What are the potential impacts of CVE-2026-56147?
The potential impacts of CVE-2026-56147 include unauthorized information disclosure and the compromise of case attachment integrity.
Who is affected by CVE-2026-56147?
CVE-2026-56147 affects users of Elastic Kibana who have low privileges but are authenticated.