CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-56152
Severity
MEDIUM
CVSS
5.3
EPSS
0.20%
Original NVD Description
Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
Related CVEs
Other vulnerabilities affecting the same vendor(s)