Improper Input Validation in Kibana's Fleet Agent Policy Management Feature
CVE-2026-49095

7.2HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-49095?

The Kibana Fleet agent policy management feature contains a critical improper input validation flaw that may allow authenticated users with Fleet management privileges to manipulate agent policy configurations. By injecting unverified values into a configuration override mechanism, an attacker could issue Elastic Agents with API keys that have escalated privileges. This misconfiguration may provide unauthorized access to sensitive Elasticsearch security indices, breaching the intended access limits set for the Fleet management role.

Affected Version(s)

Kibana 9.0.0 <= 9.3.4

Kibana 9.4.0 <= 9.4.1

Kibana 8.0.0 <= 8.19.15

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.