PT-2026-71754 · Elastic · Kibana

CVE-2026-72632

·

Published

2026-08-13

·

Updated

2026-08-19

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description An observable discrepancy in Kibana Fleet allows for information disclosure through excavation. While Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from agent listing responses, the capability accepts caller-supplied filter expressions over the stored field containing the value. These expressions are evaluated using Kibana's internal Elasticsearch privileges instead of the caller's. Since the system reports the number of matching agents, a side channel is created, allowing the full API key value to be reconstructed one character at a time through a sequence of requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-72632
BIT-KIBANA-2026-72632
CVE-2026-72632

Affected Products

Kibana