← Voltar à pesquisa de CVEs

CVE-2026-72632

Kibana

Descrição

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana-s own internal Elasticsearch privileges rather than the caller-s. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests.

CVSS 7.1EPSS 0.247%Risco 0.73
Ver fonte
Publicação
2026-08-13 20:17:24
Versões afetadas
unknown
Tipo
Aplicação web
Última alteração
2026-08-28 15:32:26
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N