CVE-2026-56152

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*

History

06 Jul 2026, 18:05

Type Values Removed Values Added
CPE cpe:2.3:a:elastic:endpoint_security:*:*:*:*:*:*:*:*
First Time Elastic endpoint Security
Elastic
References () https://discuss.elastic.co/t/elastic-defend-8-19-13-9-2-7-9-3-2-security-update-esa-2026-46 - () https://discuss.elastic.co/t/elastic-defend-8-19-13-9-2-7-9-3-2-security-update-esa-2026-46 - Vendor Advisory

01 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-01 17:16

Updated : 2026-07-06 18:05


NVD link : CVE-2026-56152

Mitre link : CVE-2026-56152

CVE.ORG link : CVE-2026-56152


JSON object : View

Products Affected

elastic

  • endpoint_security
CWE
CWE-863

Incorrect Authorization