PatchSiren cyber security CVE debrief
CVE-2026-56146 Elastic CVE debrief
CVE-2026-56146 is an Improper Access Control vulnerability in Kibana, allowing a low-privileged authenticated user with read-only Security Solution access to perform write operations on watchlist data. This could lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Affected users should review and adjust their Kibana configurations, especially Entity Analytics Watchlist settings, and restrict access to Security Solution features for low-privileged users.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Users of Kibana with Security Solution access, especially those with low-privileged authenticated users, should be aware of this vulnerability and take necessary precautions to restrict access and monitor for unusual activity.
Technical summary
CVE-2026-56146 is an Improper Access Control vulnerability in Kibana, allowing a low-privileged authenticated user with read-only Security Solution access to perform write operations on watchlist data. This could lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Users with Security Solution access, especially those with low-privileged authenticated users, should be aware of this vulnerability and take necessary precautions.
Defensive priority
Medium priority due to potential for unauthorized data modification and disclosure.
Recommended defensive actions
- Inventory and verify Kibana configurations, especially Entity Analytics Watchlist settings.
- Restrict access to Security Solution features for low-privileged users.
- Monitor for unusual activity related to watchlist data modifications.
- Apply vendor patches or updates as soon as available.
- Review and adjust user privileges and access controls.
- Perform regular security audits and vulnerability assessments.
- Implement additional monitoring and logging to detect potential security incidents.
Evidence notes
The CVE record was published on 2026-07-21T20:17:02.613Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The vulnerability is related to CWE-284 and has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor.
Official resources
-
CVE-2026-56146 CVE record
CVE.org
-
CVE-2026-56146 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T20:17:02.613Z and has not been modified since then.