CVE-2026-33461 Details
Description
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges can exploit an internal API endpoint to retrieve sensitive configuration data, including private keys and authentication tokens, that should only be accessible to users with higher-level settings privileges. The endpoint composes its response by fetching full configuration objects and returning them directly, bypassing the authorization checks enforced by the dedicated settings APIs.
A vulnerability exists in Kibana versions 8.0.0 prior to 8.19.13 and 9.0.0 prior to 9.2.8 and 9.3.0 prior to 9.3.3. This vulnerability involves incorrect authorization, allowing users with limited Fleet privileges to access an internal API endpoint. Exploitation of this endpoint can result in the unauthorized retrieval of sensitive configuration data, such as private keys and authentication tokens, which should only be available to users with higher-level settings privileges. The affected endpoint bypasses authorization checks by directly returning full configuration objects from the internal API, leading to information disclosure via privilege abuse.
Users can upgrade to Kibana versions 8.19.14, 9.2.8, or 9.3.3 to address this vulnerability. For users unable to upgrade, it is recommended to review Fleet role assignments and ensure that only trusted users have access to Fleet agent privileges. Additionally, any exposed proxy credentials should be rotated.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/kibana-8-19-14-9-2-8-9-3-3-security-update-esa-2026-24/385812 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 8.0.0, < 8.19.14 >= 9.0.0, < 9.2.8 >= 9.3.0, < 9.3.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 8, 2026 | New CVE Received | [email protected] |