PT-2026-31335 · Elastic · Kibana+1

·

CVE-2026-4498

·

Published

2026-04-08

·

Updated

2026-07-25

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description Execution with unnecessary privileges in the debug route handlers of the Fleet plugin allows an authenticated user to read index data beyond their direct Elasticsearch RBAC (Role-Based Access Control) scope. This issue occurs when a user possesses Fleet sub-feature privileges, such as those for agents, agent policies, and settings management, enabling them to abuse these privileges to access unauthorized data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-4498
BIT-KIBANA-2026-4498
CVE-2026-4498

Affected Products

Fleet
Kibana