CVE-2026-56152: Incorrect Authorization in Elastic Defend Leading to Information Disclosure
Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56152?
The severity of CVE-2026-56152 is classified as medium with a score of 5.3.
What does CVE-2026-56152 affect?
CVE-2026-56152 affects Elastic Defend, specifically related to incorrect authorization leading to information disclosure.
How do I fix CVE-2026-56152?
To fix CVE-2026-56152, ensure proper access control lists (ACLs) are implemented and configure authorization settings accordingly.
What type of vulnerability is CVE-2026-56152?
CVE-2026-56152 is an incorrect authorization vulnerability classified under CWE-863.
Who is impacted by CVE-2026-56152?
Low-privileged authenticated users are impacted by CVE-2026-56152 as they may gain access to unauthorized information.