What is CVE-2026-56147?
CVE-2026-56147 is a critical authorization bypass vulnerability in Kibana, stemming from a user-controlled key weakness (CWE-639). It allows a low-privileged authenticated user to exploit inconsistent file access logic, leading to unauthorized information disclosure and compromise of case attachment integrity. Immediate update to the latest patched version is strongly recommended.
Azərbaycanca: CVE-2026-56147 Kibana-da aşkar edilmiş kritik bir səlahiyyət yan keçmə zəifliyidir. Bu qüsur aşağı səviyyəli autentifikasiya olunmuş istifadəçiyə fayl giriş məntiqindəki uyğunsuzluq vasitəsilə icazəsiz məlumatları görməyə və iş əlavələrinin bütövlüyünü pozmağa imkan verir. Təsirlənən Kibana nümunələrini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What component of Kibana is affected by CVE-2026-56147?
This critical authorization bypass vulnerability occurs through inconsistent file access logic in Kibana.
What security measure should be taken against CVE-2026-56147?
It is strongly recommended to immediately update the affected Kibana instances to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.