PatchSiren cyber security CVE debrief
CVE-2026-56152 Elastic CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-01T17:16:37.273Z and has not been modified since then. CVE-2026-56152 is an Incorrect Authorization vulnerability (CWE-863) in Kibana that can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view. Elastic Endpoint Security users and administrators, particularly those using Kibana versions 8.6.0 to 8.19.13, 9.0.0 to 9.2.7, and 9.3.0 to 9.3.2, should review and update Kibana access controls to ensure proper authorization and monitor for suspicious activity related to response action data access. This vulnerability allows unauthorized information disclosure under certain conditions and affects Kibana versions 8.6.0 to 8.19.13, 9.0.0 to 9.2.7, and 9.3.0 to 9.3.2.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-01
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-07-01
- Advisory updated
- 2026-09-04
Who should care
Elastic Endpoint Security users and administrators, particularly those using Kibana versions 8.6.0 to 8.19.13, 9.0.0 to 9.2.7, and 9.3.0 to 9.3.2, should review and update Kibana access controls to ensure proper authorization and monitor for suspicious activity related to response action data access. This vulnerability, CVE-2026-56152, allows unauthorized information disclosure under certain conditions and affects Kibana versions 8.6.0 to 8.19.13, 9.0.0 to 9.2.7, and 9.3.0 to 9.3.2.
Technical summary
A low-privileged authenticated user can access response action data they are not authorized to view due to incorrect authorization in Kibana. This vulnerability, CVE-2026-56152, affects Kibana versions 8.6.0 to 8.19.13, 9.0.0 to 9.2.7, and 9.3.0 to 9.3.2, and allows unauthorized information disclosure under certain conditions. Elastic Endpoint Security users and administrators should review and update Kibana access controls to ensure proper authorization and monitor for suspicious activity related to response action data access.
Defensive priority
Medium-priority defensive actions are recommended due to the potential for unauthorized information disclosure.
Recommended defensive actions
- Review and update Kibana access controls to ensure proper authorization
- Monitor for suspicious activity related to response action data access
- Apply vendor-provided security updates to affected Kibana versions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from the NVD and CVE Program indicates a medium-severity vulnerability in Kibana, allowing unauthorized information disclosure under certain conditions. The vulnerability, CVE-2026-56152, affects Kibana versions 8.6.0 to 8.19.13, 9.0.0 to 9.2.7, and 9.3.0 to 9.3.2. Elastic Endpoint Security users and administrators should review and update Kibana access controls to ensure proper authorization and monitor for suspicious activity related to response action data access. The CVE record was published on 2026-07-01T17:16:37.273Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-56152 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-56152
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-56152 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56152
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-13-9-2-7-9-3-2-security-update-esa-2026-46/387443
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.