Unrated severityNVD Advisory· Published Jul 1, 2026· Updated Jul 1, 2026
Incorrect Authorization in Elastic Defend Leading to Information Disclosure
CVE-2026-56152
Description
Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.