Authorization bypass through user-controlled key in Kibana - CVE-2026-56147

 

Authorization bypass through user-controlled key in Kibana - CVE-2026-56147

Published: July 22, 2026


Vulnerability identifier: #VU139143
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56147
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify or delete protected case attachments.

The vulnerability exists due to authorization bypass through user-controlled key in Kibana file access authorization logic when handling access to case attachments across feature areas. A remote user can retrieve, modify, or delete case attachments belonging to feature areas they are not authorized to access to disclose sensitive information and modify or delete protected case attachments.

Only deployments where users have been granted Files Management or Shared Images feature access are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-56147

Install security update from vendor's website.

Kibana - addressed in versions 8.19.18, 9.3.7, 9.4.3

External References

Related Security Bulletins