Executive brief
Kibana is a data visualization and management platform for the Elastic Stack. A security flaw allows a user with management permissions in one organizational 'space' to view sensitive configuration details from other spaces they are not authorized to access. This could lead to the exposure of internal infrastructure details, policy names, and operational identifiers across different business units or projects.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the Kibana Fleet component. The vulnerability is rooted in an internal enrollment endpoint that utilizes an unscoped internal client, effectively bypassing space-scoped access controls. An attacker with Fleet agent management privileges in at least one space can exploit this to retrieve Fleet Server policy details, operational identifiers, and infrastructure linkage details from other spaces. The attack is reachable over the network and requires low-privileged authentication. The issue is resolved in Kibana versions 8.19.14, 9.2.8, and 9.3.3.
Affected products
- Elastic Kibana 8.0.0 - 8.19.13, 9.0.0 - 9.2.7, 9.3.0 - 9.3.2
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched