Improper access control in Kibana - CVE-2026-56146

 

Improper access control in Kibana - CVE-2026-56146

Published: July 22, 2026


Vulnerability identifier: #VU139133
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56146
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify watchlist configuration and disclose sensitive information.

The vulnerability exists due to improper access control in the Entity Analytics Watchlist configuration functionality when handling watchlist operations. A remote user can perform write operations on watchlist data to modify watchlist configuration and disclose sensitive information.

Only deployments with Security Solution features enabled at the Platinum license tier or above are vulnerable, and the information disclosure impact requires the Entity Store feature to be enabled.


Affected software

Kibana

How to mitigate CVE-2026-56146

Install security update from vendor's website.

Kibana - update to 9.4.3

External References

Related Security Bulletins