Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.
Affected Versions:
- 9.4.x: All versions from 9.4.0 up to and including 9.4.2
Users on the 8.x release line and versions prior to 9.4.0 are not affected. The Entity Analytics Watchlists feature was introduced in 9.4.0 and is not present in earlier versions.
Affected Configurations:
- Kibana deployments with Security Solution features enabled at the Platinum license tier or above, including trial licenses, where users have been granted a read-only Security Solution feature privilege. For the maximum impact scenario involving potential information disclosure, the Entity Store feature must also be enabled in the deployment.
Solutions and Mitigations:
The issue is resolved in version 9.4.3.
For Users that Cannot Upgrade:
- There are no workarounds for this vulnerability.
Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.
Elastic Cloud Serverless
Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.
Severity: CVSSv3.1: Medium ( 5.4 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVE ID: CVE-2026-56146
Problem Type: CWE-284 - Improper Access Control