← Volver al buscador de CVEs

CVE-2026-72632

Kibana

Descripción

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana-s own internal Elasticsearch privileges rather than the caller-s. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests.

CVSS 7.1EPSS 0.247%Riesgo 0.73
Ver fuente
Publicación
2026-08-13 20:17:24
Versiones afectadas
unknown
Tipo
Aplicación web
Última modificación
2026-08-28 15:32:26
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N