Junglewise Threat Intelligence

CVE-2026-56146: Elastic Kibana improper access control in Entity Analytics Watchlist

CVE-2026-56146 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a popular data visualization and management platform for the Elastic Stack, contains a security flaw in its Entity Analytics Watchlist feature. An internal user with limited, read-only access could bypass security controls to modify watchlist configurations or potentially view sensitive data they are not authorized to see. This could lead to unauthorized changes in security monitoring settings or the exposure of internal business data.

Technical details

An improper access control vulnerability (CWE-284/CWE-863) exists in Kibana's Entity Analytics Watchlist feature, introduced in version 9.4.0. The flaw allows a low-privileged authenticated user with read-only Security Solution access to perform write operations on watchlist data. In specific configurations where the Entity Store feature is enabled, this could also lead to unauthorized information disclosure beyond the user's assigned scope. The vulnerability affects Kibana deployments at the Platinum license tier or above (including trials) and is resolved in version 9.4.3.

Affected products

  • Elastic Kibana 9.4.0 to 9.4.2

Timeline

  • 2026-07-21: advisory: Elastic published security update ESA-2026-58
  • 2026-07-21: patched: Fixed in Kibana version 9.4.3

References

Related threats