PT-2026-44537 · Elastic · Elasticsearch+1

Ismisepaul

+1

·

Published

2026-05-28

·

Updated

2026-06-01

·

CVE-2026-49095

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description Improper input validation in the Kibana Fleet agent policy management feature allows an authenticated user with Fleet management privileges to escalate privileges. By injecting values into a configuration override mechanism that lacks adequate validation, an attacker can cause Elastic Agents to be issued API keys with elevated Elasticsearch privileges. This may grant unauthorized read and write access to sensitive Elasticsearch security indices, exceeding the intended permissions of the Fleet management role.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-49095
BIT-KIBANA-2026-49095
CVE-2026-49095

Affected Products

Elasticsearch
Kibana