Description
Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization flaw (CWE‑863) in Elastic Defend allows a low‑privileged authenticated user to access response‑action data that they should not be able to see. The vulnerability is triggered when the endpoint that returns action data is not properly constrained by access‑control lists, leading to the disclosure of confidential control information.

Affected Systems

All installations of Elastic Defend that are running an affected version could be vulnerable. The advisory does not list specific release numbers, so any deployment that has Administrators should verify the version of Elastic Defend and apply the latest patch once available.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity. An EPSS score of less than 1 % indicates a very low likelihood of exploitation at this time, and the vulnerability is not yet listed in the CISA KEV catalog. Because an attacker must first be authenticated with a low‑privilege account, the attack path is limited; however, once authenticated the exploit is straightforward and results in the disclosure of otherwise protected action data.

Generated by OpenCVE AI on July 21, 2026 at 13:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Elastic Defend security patch or upgrade to a version that contains the authorization fix.
  • If a patch is not yet available, disable or restrict the endpoint that exposes response‑ unusual access attempts.
  • Review and enforce proper access‑control lists on all response‑action endpoints so that only authorized users can retrieve that data.

Generated by OpenCVE AI on July 21, 2026 at 13:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Title Incorrect Authorization in Elastic Defend Leading to Information Disclosure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-01T17:25:07.934Z

Reserved: 2026-06-19T11:01:02.535Z

Link: CVE-2026-56152

cve-icon Vulnrichment

Updated: 2026-07-01T17:20:48.901Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:00:05Z

Weaknesses