SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-56146

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Kibana is vulnerable due to improper access control, allowing low-privileged authenticated users with read-only Security Solution access to perform unauthorized write operations on Entity Analytics Watchlist configurations. This could lead to unauthorized modifications and potential information disclosure, especially under certain deployment conditions where users might access data beyond their authorized scope. Organizations using Kibana should prioritize addressing this vulnerability to prevent potential misuse of sensitive data.

CVE
CVE-2026-56146
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%

Original NVD Description

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.

Related CVEs

Other vulnerabilities affecting the same vendor(s)