Executive brief
Elastic Defend, a security tool used to protect servers and workstations, contains a flaw that could allow unauthorized users to view sensitive security response data. A person with low-level access to the system could potentially see information about security actions they are not supposed to access. This could lead to the exposure of internal security operations and data, though it requires specific conditions to be met. The issue has been fixed in the latest software updates.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Elastic Defend when handling response actions. The flaw stems from functionality not being properly constrained by Access Control Lists (ACLs), specifically CAPEC-1. An authenticated attacker with low privileges can, under certain conditions, bypass these constraints to view response action data they are not authorized to access. The attack vector is network-based, though it requires high complexity and existing user authentication. The vulnerability is remediated in versions 8.19.13, 9.2.7, and 9.3.2.
Affected products
- Elastic Elastic Defend 8.6.0 to 8.19.12, 9.0.0 to 9.2.6, 9.3.0 to 9.3.1
Timeline
- 2026-07-01: advisory
- 2026-07-01: disclosed
- 2026-07-01: patched