Description
Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensitive credential material that should be restricted to users with Fleet settings administrative access. Successful exploitation could allow an attacker to obtain private cryptographic key material configured for Fleet Server host connections, potentially enabling impersonation of trusted Fleet infrastructure components in deployments where those keys are actively used.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply patch
AI Analysis

Impact

An incorrect authorization check in Kibana allows an authenticated user with limited Fleet management privileges to access data that should be restricted to users with administrative access to Fleet settings. This flaw can expose private cryptographic key material used for Fleet Server host connections, creating the possibility for an attacker to impersonate trusted Fleet infrastructure components. The vulnerability is classified as CWE‑863 and can lead to a significant compromise of confidentiality for sensitive operational assets.

Affected Systems

Elastic Kibana is affected. The CVE description does not specify an affected version range; users should verify that their deployment runs a version prior to the published security update and consider upgrading if necessary.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, so the current exploitation likelihood is unknown. This issue is not listed in the CISA KEV catalog. The likely attack requires an authenticated Kibana session and may be carried out by an insider or an attacker who has compromised a user account with limited Fleet privileges. Successful exploitation could allow the attacker to read sensitive credential material and potentially impersonate Fleet services in affected deployments.

Generated by OpenCVE AI on October 6, 2026 at 20:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kibana to a version that includes the security fix for the authorization flaw
  • Restrict Fleet settings access by ensuring only administrative roles have permission to view and manage credential material
  • Audit role definitions and enforce least‑privilege principles to minimize the number of users with Fleet management rights

Generated by OpenCVE AI on October 6, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensitive credential material that should be restricted to users with Fleet settings administrative access. Successful exploitation could allow an attacker to obtain private cryptographic key material configured for Fleet Server host connections, potentially enabling impersonation of trusted Fleet infrastructure components in deployments where those keys are actively used.
Title Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:54:33.779Z

Reserved: 2026-09-29T02:06:02.426Z

Link: CVE-2026-102412

cve-icon Vulnrichment

Updated: 2026-10-06T19:54:29.577Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:13.330

Modified: 2026-10-06T20:17:13.330

Link: CVE-2026-102412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:06Z

Weaknesses