Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-56152

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Jul 01, 2026
Vendor unknown

Description

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

References