Authorization Flaw in Kibana Leads to Information Disclosure by Elastic
CVE-2026-33460
4.3MEDIUM
What is CVE-2026-33460?
An authorization flaw exists in Kibana that allows users with Fleet agent management privileges to access sensitive policy details across different spaces. This vulnerability arises from improper enforcement of space-scoped access controls, allowing unauthorized retrieval of operational identifiers, policy names, and infrastructure details via an internal endpoint. As a result, users may exploit this weakness to gain access to information not meant for them, highlighting the need for enhanced security measures.
Affected Version(s)
Kibana 9.3.0 <= 9.3.2
Kibana 9.0.0 <= 9.2.7
Kibana 8.0.0 <= 8.19.13