---
id: CVE-2026-56152
title: >-
  Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized
  information disclosure via Accessing Functionality Not Properly Constrained by
  ACLs (CAPEC-1)
summary: >-
  Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized
  information disclosure via Accessing Functionality Not Properly Constrained by
  ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user
  can access …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: elastic
product: endpoint_security
affected:
  - 'endpoint_security >= 8.6.0, < 8.19.13'
  - 'endpoint_security >= 9.0.0, < 9.2.7'
  - 'endpoint_security >= 9.3.0, < 9.3.2'
patched:
  - endpoint_security 9.3.2
published: '2026-07-01'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56152'
references:
  - url: >-
      https://discuss.elastic.co/t/kibana-8-19-13-9-2-7-9-3-2-security-update-esa-2026-46/387443
    label: security@elastic.co
tags:
  - nvd
epss: 0.00305
epssPercentile: 0.20665
ingestedAt: '2026-09-05T13:39:55.641Z'
---

## Overview

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

## Affected

- `endpoint_security >= 8.6.0, < 8.19.13`
- `endpoint_security >= 9.0.0, < 9.2.7`
- `endpoint_security >= 9.3.0, < 9.3.2`

## Remediation

Upgrade past the affected range:

- `endpoint_security 9.3.2`
