Improper Input Validation in Kibana's Fleet Agent Policy Management Feature
CVE-2026-49095
7.2HIGH
What is CVE-2026-49095?
The Kibana Fleet agent policy management feature contains a critical improper input validation flaw that may allow authenticated users with Fleet management privileges to manipulate agent policy configurations. By injecting unverified values into a configuration override mechanism, an attacker could issue Elastic Agents with API keys that have escalated privileges. This misconfiguration may provide unauthorized access to sensitive Elasticsearch security indices, breaching the intended access limits set for the Fleet management role.
Affected Version(s)
Kibana 9.0.0 <= 9.3.4
Kibana 9.4.0 <= 9.4.1
Kibana 8.0.0 <= 8.19.15