PT-2026-71754 · Elastic · Kibana
CVE-2026-72632
·
Published
2026-08-13
·
Updated
2026-08-19
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kibana (affected versions not specified)
Description
An observable discrepancy in Kibana Fleet allows for information disclosure through excavation. While Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from agent listing responses, the capability accepts caller-supplied filter expressions over the stored field containing the value. These expressions are evaluated using Kibana's internal Elasticsearch privileges instead of the caller's. Since the system reports the number of matching agents, a side channel is created, allowing the full API key value to be reconstructed one character at a time through a sequence of requests.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kibana