PT-2026-31335 · Elastic · Kibana+1

Ismisepaul

+1

·

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-4498

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description Kibana’s Fleet plugin debug route handlers exhibit execution with unnecessary privileges, potentially allowing authenticated users with Fleet sub-feature privileges to read index data beyond their authorized Elasticsearch RBAC scope. This occurs through privilege abuse.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-4498
BIT-KIBANA-2026-4498
CVE-2026-4498

Affected Products

Fleet
Kibana