Description
Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization flaw (CWE‑863) in Elastic Defend allows a low‑privileged authenticated user to access response‑action data that they should not be able to see. The vulnerability is triggered when the endpoint that returns action data is not properly constrained by access‑control lists, leading to the disclosure of confidential control information.

Affected Systems

All installations of Elastic Defend that may expose the vulnerable endpoint could be affected. The advisory does not list specific release numbers, so administrators should check the installed version against vendor documentation and confirm whether the environment meets the conditions described in the advisory.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity. An EPSS score of less than 1 % indicates a very low likelihood of exploitation at this time, and the vulnerability is not yet listed in the CISA KEV catalog. Because an attacker must first be authenticated with a low‑privilege account, the attack path is limited; however, once authenticated the exploit is straightforward and results in the disclosure of otherwise protected action data.

Generated by OpenCVE AI on August 1, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Determine the installed Elastic Defend version and compare it with vendor’s advisory to confirm whether the installation is affected.
  • Check the vendor’s website or support channels for an update or patch that addresses the authorization flaw and apply it as soon as it becomes available.
  • If no patch is yet available, restrict access to the endpoint that serves response‑action data by enforcing the proper access‑control lists or by limiting network access so that only authorized users can retrieve that data.

Generated by OpenCVE AI on August 1, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elastic Defend
Vendors & Products Elastic
Elastic elastic Defend

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Title Incorrect Authorization in Elastic Defend Leading to Information Disclosure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Elastic Elastic Defend Endpoint Security
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-01T17:25:07.934Z

Reserved: 2026-06-19T11:01:02.535Z

Link: CVE-2026-56152

cve-icon Vulnrichment

Updated: 2026-07-01T17:20:48.901Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-01T17:16:37.273

Modified: 2026-07-06T18:05:39.700

Link: CVE-2026-56152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T23:00:05Z

Weaknesses