Skip to content

[Security Solution][Bug] An inappropriate error message is shown on deleting added notes when user is having READ permission #246314

@divyaaghi-qasource

Description

@divyaaghi-qasource

Describe the bug:
Delete button is clickable for deleting the added notes with READ permission. Moreover an inappropriate error message is shown on deleting added notes when user is having READ permission

Kibana/Elasticsearch Stack version:

VERSION: 9.3.0

BUILD: 94544

COMMIT: bf8c75b853e390db94045bdc41c8fc553ac848b9

Pre Conditions:
1.Kibana v9.3.0 snapshot must be present.
2. Some notes must be added.
3.User must have only READ permission for Notes.

Steps to reproduce:

1.Login with the user created.
2.Navigate to More>Investigations>Notes
3.Select the note added.
4.Click on Bulk actions>Delete selected note.
5.Observe that delete button is clickable
6.On clicking, an inappropriate error message is shown on deleting added notes when user is having READ permission

Current behavior:
Delete button is clickable for deleting the added notes with READ permission. Moreover an inappropriate error message is shown on deleting added notes when user is having READ permission

Expected behavior:
Delete button should not be clickable for deleting the added notes with READ permission and a user friendly error message should be shown on deleting added notes when user is having READ permission

Screenshots (if relevant):

Image

Screen recording:

Notes.-.Kibana.-.Google.Chrome.2025-12-15.13-08-09.mp4

Metadata

Metadata

Assignees

Labels

QA:ValidatedIssue has been validated by QATeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeamTeam:Threat Hunting:InvestigationsSecurity Solution Threat Hunting Investigations TeambugFixes for quality problems that affect the customer experienceimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.v9.3.0

Type

No fields configured for Bug.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions