{"id":"CVE-2026-56152","title":"Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1)","summary":"Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access …","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-863"],"vendor":"elastic","product":"endpoint_security","affected":["endpoint_security >= 8.6.0, < 8.19.13","endpoint_security >= 9.0.0, < 9.2.7","endpoint_security >= 9.3.0, < 9.3.2"],"patched":["endpoint_security 9.3.2"],"published":"2026-07-01","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56152","references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-13-9-2-7-9-3-2-security-update-esa-2026-46/387443","label":"security@elastic.co"}],"tags":["nvd"],"epss":0.00305,"epssPercentile":0.23407,"ingestedAt":"2026-09-05T13:39:55.641Z","slug":"CVE-2026-56152","body":"## Overview\n\nIncorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.\n\n## Affected\n\n- `endpoint_security >= 8.6.0, < 8.19.13`\n- `endpoint_security >= 9.0.0, < 9.2.7`\n- `endpoint_security >= 9.3.0, < 9.3.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `endpoint_security 9.3.2`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}