Junglewise Threat Intelligence

CVE-2026-33461: Elastic Kibana incorrect authorization in Fleet component

CVE-2026-33461 · Severity: high · CVSS 7.7 · Published 2026-04-08

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and management platform for the Elastic Stack. A security flaw in the Fleet management component allows users with low-level permissions to access sensitive configuration data they should not be able to see. This could result in the exposure of private keys and authentication tokens, potentially allowing an attacker to further compromise the environment or intercept data.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Kibana's Fleet component. The flaw resides in an internal API endpoint that fails to properly enforce authorization checks when fetching configuration objects. Specifically, the endpoint returns full configuration objects directly, bypassing the stricter access controls implemented in dedicated settings APIs. An authenticated attacker with 'Fleet Agents' privileges but lacking 'Fleet Settings' privileges can exploit this to disclose sensitive secrets like private keys and tokens. The issue is resolved in Kibana versions 8.19.14, 9.2.8, and 9.3.3.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.13, 9.0.0 to 9.2.7, 9.3.0 to 9.3.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References

Related threats