Vulnerabilities
Vulnerable Software
Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-07-01


Contact Us

Shodan ® - All rights reserved