Authorization bypass through user-controlled key in Kibana - CVE-2026-56147
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify or delete protected case attachments.
The vulnerability exists due to authorization bypass through user-controlled key in Kibana file access authorization logic when handling access to case attachments across feature areas. A remote user can retrieve, modify, or delete case attachments belonging to feature areas they are not authorized to access to disclose sensitive information and modify or delete protected case attachments.
Only deployments where users have been granted Files Management or Shared Images feature access are vulnerable.