PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-56146 Elastic CVE debrief

CVE-2026-56146 is an Improper Access Control vulnerability in Kibana, allowing a low-privileged authenticated user with read-only Security Solution access to perform write operations on watchlist data. This could lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Affected users should review and adjust their Kibana configurations, especially Entity Analytics Watchlist settings, and restrict access to Security Solution features for low-privileged users.

Vendor
Elastic
Product
Kibana
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Users of Kibana with Security Solution access, especially those with low-privileged authenticated users, should be aware of this vulnerability and take necessary precautions to restrict access and monitor for unusual activity.

Technical summary

CVE-2026-56146 is an Improper Access Control vulnerability in Kibana, allowing a low-privileged authenticated user with read-only Security Solution access to perform write operations on watchlist data. This could lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Users with Security Solution access, especially those with low-privileged authenticated users, should be aware of this vulnerability and take necessary precautions.

Defensive priority

Medium priority due to potential for unauthorized data modification and disclosure.

Recommended defensive actions

  • Inventory and verify Kibana configurations, especially Entity Analytics Watchlist settings.
  • Restrict access to Security Solution features for low-privileged users.
  • Monitor for unusual activity related to watchlist data modifications.
  • Apply vendor patches or updates as soon as available.
  • Review and adjust user privileges and access controls.
  • Perform regular security audits and vulnerability assessments.
  • Implement additional monitoring and logging to detect potential security incidents.

Evidence notes

The CVE record was published on 2026-07-21T20:17:02.613Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The vulnerability is related to CWE-284 and has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T20:17:02.613Z and has not been modified since then.