Description
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

An authorization flaw (CWE-863) in Elastic's Kibana allows a low-privileged authenticated user to access response-action data they should not see. The flaw arises when the endpoint that returns action data is not properly constrained by ACLs, leading to the disclosure of potentially confidential control information. This vulnerability permits unauthorized information disclosure through the improper enforcement of access controls (CAPEC-1).

Affected Systems

All installations of Elastic Kibana that expose the vulnerable endpoint could be affected. The advisory does not list specific release numbers, so administrators should check the installed Kibana version against vendor documentation and confirm whether the environment meets the conditions described in the advisory.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity. An EPSS score of less than 1% indicates a very low likelihood of exploitation at this time, and the vulnerability is not yet listed in the CISA KEV catalog. Because an attacker must first be authenticated with a low-privilege account, the attack path is limited; however, once authenticated the exploit is straightforward and results in the disclosure of otherwise protected action data.

Generated by OpenCVE AI on September 4, 2026 at 23:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Determine the installed Elastic Kibana version and compare it with vendor’s advisory to confirm whether the installation is affected.
  • Check the vendor’s website or support channels for an update or patch that addresses the authorization flaw and apply it as soon as it becomes available.
  • If no patch is yet available, restrict access to the endpoint that serves response-action data by enforcing the proper access-control lists or by limiting network access so that only authorized users can retrieve that data.

Generated by OpenCVE AI on September 4, 2026 at 23:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:30:00 +0000


Fri, 04 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view. Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Title Incorrect Authorization in Elastic Defend Leading to Information Disclosure Incorrect Authorization in Kibana Leading to Information Disclosure
References

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elastic Defend
Vendors & Products Elastic
Elastic elastic Defend

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Title Incorrect Authorization in Elastic Defend Leading to Information Disclosure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Elastic Elastic Defend Endpoint Security
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-04T15:03:45.846Z

Reserved: 2026-06-19T11:01:02.535Z

Link: CVE-2026-56152

cve-icon Vulnrichment

Updated: 2026-07-01T17:20:48.901Z

cve-icon NVD

Status : Modified

Published: 2026-07-01T17:16:37.273

Modified: 2026-09-04T15:17:33.717

Link: CVE-2026-56152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T23:45:17Z

Weaknesses