Description
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Access Control in Kibana allows a low‑privileged authenticated user with read‑only Security Solution access to perform write operations on the Entity Analytics Watchlist configuration, a capability that should be restricted to elevated users. The flaw can also enable that user to access data beyond their authorized scope, potentially exposing sensitive information. The underlying weakness corresponds to CWE‑863 (improper authorization) and is also described as a CWE‑284 (Improper Access Control).

Affected Systems

Elastic Kibana installations of any supported version are potentially vulnerable, as no specific version was identified in the advisory. The issue is documented for deployments where read‑only users retain write capabilities to watchlist data. Users should consult the Elastic Security Update references for more detailed guidance and to confirm which releases contain the fix.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4, indicating moderate severity, and an EPSS of less than 1 %, suggesting a low likelihood of exploitation at this time. It is not listed in the CISA KEV catalog. An attacker must first authenticate with a low‑privileged Kibana account and then exploit the improper permission check to alter watchlist entries or view restricted data. The attack is localized to Kibana and does not require remote, unauthenticated access, but the impact on integrity and confidentiality can be significant for organizations tracking sensitive analytics.

Generated by OpenCVE AI on July 30, 2026 at 16:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the current Kibana version against Elastic’s Security Update references and confirm if the issue is already addressed; if not, plan to upgrade or apply the available patch as soon as it is released.
  • Restrict the read‑only Security Solution role so it has no write permissions to Entity Analytics Watchlists or other sensitive configurations. Verify that only users with appropriate administrative rights can modify watchlist data.
  • Monitor Kibana audit logs for unexpected write operations on watchlist configurations and investigate any anomalies promptly.

Generated by OpenCVE AI on July 30, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.
Title Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-22T18:25:16.770Z

Reserved: 2026-06-19T11:01:02.535Z

Link: CVE-2026-56146

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:59.616Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:45:04Z

Weaknesses