Sploitus

CVE-2026-56146

No indexed exploits for CVE-2026-56146 yet

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.

Affected products
Kibana
Elastic Kibana
< 9.4.3
CVSS 3.1
5.4 MEDIUM
EPSS
0.2% (7th percentile)
Weakness
CWE-863
NVD status
Analyzed
Published
2026-07-21
Attack patterns
CAPEC-122
CVE-2026-56146 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-56146 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-56146 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.