Improper access control in Kibana - CVE-2026-56146
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to modify watchlist configuration and disclose sensitive information.
The vulnerability exists due to improper access control in the Entity Analytics Watchlist configuration functionality when handling watchlist operations. A remote user can perform write operations on watchlist data to modify watchlist configuration and disclose sensitive information.
Only deployments with Security Solution features enabled at the Platinum license tier or above are vulnerable, and the information disclosure impact requires the Entity Store feature to be enabled.