Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
History

Fri, 04 Sep 2026 15:30:00 +0000


Fri, 04 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view. Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Title Incorrect Authorization in Elastic Defend Leading to Information Disclosure Incorrect Authorization in Kibana Leading to Information Disclosure
References

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elastic Defend
Vendors & Products Elastic
Elastic elastic Defend

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Title Incorrect Authorization in Elastic Defend Leading to Information Disclosure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2026-07-01T16:32:21.830Z

Updated: 2026-09-04T15:03:45.846Z

Reserved: 2026-06-19T11:01:02.535Z

Link: CVE-2026-56152

cve-icon Vulnrichment

Updated: 2026-07-01T17:20:48.901Z

cve-icon NVD

Status : Modified

Published: 2026-07-01T17:16:37.273

Modified: 2026-09-04T15:17:33.717

Link: CVE-2026-56152

cve-icon Redhat

No data.