CVE-2026-56152: Elastic Endpoint Security

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

Affected products

  • Elastic Endpoint Security: from 8.6.0, before 8.19.13 (fixed in 8.19.13); from 9.0.0, before 9.2.7 (fixed in 9.2.7); from 9.3.0, before 9.3.2 (fixed in 9.3.2)

Published 2026-07-01. Last modified 2026-09-04.