Executive brief
A vulnerability in Kibana's Fleet management tool could allow an authorized administrator to gain higher-level access than intended. By manipulating configuration settings, an attacker could grant themselves broad read and write access to sensitive security data within the Elasticsearch database. This could lead to unauthorized data exposure or the modification of critical security logs and settings.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Kibana Fleet agent policy management component. Authenticated users with the 'fleet-all' application privilege can exploit a configuration override mechanism by injecting unvalidated values into agent policies. This manipulation causes Elastic Agents to be issued API keys with elevated Elasticsearch privileges. Consequently, an attacker can gain unauthorized read and write access to sensitive Elasticsearch security indices, bypassing the restrictions normally associated with the Fleet management role. The issue is resolved in Kibana versions 8.19.16, 9.3.5, and 9.4.2.
Affected products
- Elastic Kibana 8.0.0 to 8.19.15, 9.0.0 to 9.3.4, 9.4.0 to 9.4.1
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory
- 2026-05-28: patched