Impact
An authorization flaw (CWE‑863) in Elastic Defend allows a low‑privileged authenticated user to access response‑action data that they should not be able to see. The vulnerability is triggered when the endpoint that returns action data is not properly constrained by access‑control lists, leading to the disclosure of confidential control information.
Affected Systems
All installations of Elastic Defend that are running an affected version could be vulnerable. The advisory does not list specific release numbers, so any deployment that has Administrators should verify the version of Elastic Defend and apply the latest patch once available.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. An EPSS score of less than 1 % indicates a very low likelihood of exploitation at this time, and the vulnerability is not yet listed in the CISA KEV catalog. Because an attacker must first be authenticated with a low‑privilege account, the attack path is limited; however, once authenticated the exploit is straightforward and results in the disclosure of otherwise protected action data.
OpenCVE Enrichment