Junglewise Threat Intelligence

CVE-2026-56147: Elastic Kibana authorization bypass in case attachments

CVE-2026-56147 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and management platform used to analyze large datasets. A security flaw allows users with limited permissions to bypass access controls and view, modify, or delete sensitive file attachments, such as those used in security investigations. This could lead to the exposure of confidential data or the tampering of evidence within the platform's case management system.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in Kibana's file access authorization logic. The vulnerability stems from an inconsistency between the access control check mechanism and the resource retrieval mechanism. An authenticated attacker with 'Files Management' or 'Shared Images' permissions can manipulate user-controlled keys to access case attachments (such as those in the Security Solution) that they are not authorized to view. This allows for unauthorized information disclosure and compromise of data integrity. The issue is resolved in Kibana versions 8.19.18, 9.3.7, and 9.4.3.

Affected products

  • Elastic Kibana 8.7.0 to 8.19.17, 9.0.0 to 9.3.6, 9.4.0 to 9.4.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory
  • 2026-07-21: patched: Fixed in 8.19.18, 9.3.7, and 9.4.3

References

Related threats