CVE-2026-56147: CWE-639 Authorization Bypass Through User-Controlled Key in Elastic Kibana
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and delete case attachments that belong to feature areas they are not authorized to access. Because the access control check and the resource retrieval use different resolution mechanisms, an authenticated attacker with limited file management permissions can obtain the contents of, modify, or delete protected case attachments — such as those associated with Security Solution cases — without holding the privileges required to access those features.
AI Analysis
Technical Summary
This vulnerability (CWE-639) in Kibana involves an authorization bypass through a user-controlled key, allowing authenticated users with limited file management permissions to retrieve, modify, or delete case attachments belonging to unauthorized feature areas. The root cause is an inconsistency between the access control check and the resource retrieval mechanisms, which do not align properly. As a result, an attacker can bypass intended access restrictions and compromise case attachment confidentiality and integrity without having the required privileges for those features.
Potential Impact
An attacker with low privileges can access sensitive case attachments they should not be authorized to view or modify, leading to unauthorized information disclosure and integrity compromise of case attachments. This impacts confidentiality and integrity but does not affect availability. The vulnerability specifically threatens protected case attachments, including those associated with Security Solution cases.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. Until a fix is available, restrict access to Kibana to trusted users and review permissions to minimize exposure. Avoid granting unnecessary file management permissions to low-privileged users.
CVE-2026-56147: CWE-639 Authorization Bypass Through User-Controlled Key in Elastic Kibana
Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and delete case attachments that belong to feature areas they are not authorized to access. Because the access control check and the resource retrieval use different resolution mechanisms, an authenticated attacker with limited file management permissions can obtain the contents of, modify, or delete protected case attachments — such as those associated with Security Solution cases — without holding the privileges required to access those features.
CVSS v3.1
Score 7.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-639) in Kibana involves an authorization bypass through a user-controlled key, allowing authenticated users with limited file management permissions to retrieve, modify, or delete case attachments belonging to unauthorized feature areas. The root cause is an inconsistency between the access control check and the resource retrieval mechanisms, which do not align properly. As a result, an attacker can bypass intended access restrictions and compromise case attachment confidentiality and integrity without having the required privileges for those features.
Potential Impact
An attacker with low privileges can access sensitive case attachments they should not be authorized to view or modify, leading to unauthorized information disclosure and integrity compromise of case attachments. This impacts confidentiality and integrity but does not affect availability. The vulnerability specifically threatens protected case attachments, including those associated with Security Solution cases.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor communications for updates. Until a fix is available, restrict access to Kibana to trusted users and review permissions to minimize exposure. Avoid granting unnecessary file management permissions to low-privileged users.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-83mc-f7wh-6hxj
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-56147"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a600aa69c2644c7f8fdffa6
Added to database: 07/22/2026, 00:11:18 UTC
Last enriched: 07/22/2026, 00:41:26 UTC
Last updated: 09/01/2026, 10:52:09 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.