← Volver al buscador de CVEs

CVE-2026-72670

Kibana

Descripción

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be authorized to view.

CVSS 7.7EPSS 0.335%Riesgo 0.79
Ver fuente
Publicación
2026-08-13 20:17:27
Versiones afectadas
unknown
Tipo
Aplicación web
Última modificación
2026-08-28 15:32:26
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N