PT-2026-31333 · Elastic · Kibana

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-33460

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description An incorrect authorization issue in Kibana can lead to cross-space information disclosure through privilege abuse. A user with Fleet agent management privileges in one Kibana space can retrieve Fleet Server policy details from other spaces. This occurs because an internal enrollment endpoint bypasses space-scoped access controls by using an unscoped internal client, revealing operational identifiers, policy names, management state, and infrastructure linkage details from unauthorized spaces.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-33460
BIT-KIBANA-2026-33460
CVE-2026-33460

Affected Products

Kibana