PT-2026-31335 · Elastic · Kibana+1
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kibana (affected versions not specified)
Description
Execution with unnecessary privileges in the debug route handlers of the Fleet plugin allows an authenticated user to read index data beyond their direct Elasticsearch RBAC (Role-Based Access Control) scope. This issue occurs when a user possesses Fleet sub-feature privileges, such as those for agents, agent policies, and settings management, enabling them to abuse these privileges to access unauthorized data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fleet
Kibana