Description
A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be authorized to view.
Published: 2026-08-13
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A user with only read‑policy privileges in Kibana can access the entire Fleet proxy configuration, including authentication credentials and private keys. This reveals sensitive data that should be protected by higher‑level Fleet privileges, potentially allowing attackers to compromise downstream services that rely on those credentials.

Affected Systems

The vulnerability affects Elastic Kibana. No specific product version is listed in the available data; the CVE applies to the Kibana component wherever the described privilege model exists.

Risk and Exploitability

The CVSS score of 7.7 indicates a high risk of exposure; the EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be able to log in as a user with read‑policy rights, which is a relatively low barrier under many configurations. Once privilege is granted, the attacker can read the full Fleet proxy configuration and exfiltrate credentials and key material, leading to potential lateral movement or compromise of external systems. The lack of additional mitigations in the environment increases the likelihood of exploitation.

Generated by OpenCVE AI on August 13, 2026 at 21:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Escalate the privilege model to ensure that only users with full Fleet privileges can read proxy configurations; remove read‑policy rights from users who do not need them.
  • Apply the latest Kibana security patch 8.19.20+ (or the equivalent 9.4.5+ release) to address the exposed configuration access path.
  • If an update is not immediately available, isolate Fleet proxy configuration storage by moving it to a secure, access‑controlled repository or encrypt the configuration to prevent unauthorized reading.

Generated by OpenCVE AI on August 13, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be authorized to view.
Title Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:33:18.466Z

Reserved: 2026-08-10T11:17:49.704Z

Link: CVE-2026-72670

cve-icon Vulnrichment

Updated: 2026-08-13T20:33:14.864Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:27.530

Modified: 2026-08-28T15:32:26.217

Link: CVE-2026-72670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor