Executive brief
Kibana Fleet, which manages deployment policies for Elastic security integrations, contains an authorization flaw that allows authenticated users to escalate their privileges. An administrator restricted to managing only endpoint security policies could exploit this to convert their policies into configurations for other integrations, potentially gaining access to sensitive settings they should not control.
Technical details
The vulnerability is an incorrect authorization (CWE-863) in Kibana Fleet's integration policy update mechanism. When an existing policy is updated, the access control check evaluates the original stored integration type rather than the replacement integration supplied in the update request. This allows an authenticated user with Elastic Defend endpoint policy management privilege to modify a policy they administer by changing its integration type to an unrestricted one and injecting that integration's configuration. The flaw requires authentication and network access to the Kibana instance. Patches are available in Kibana 8.19.20, 9.4.5, and 9.5.1.
Affected products
- Elastic Kibana 8.19.0–8.19.19, 9.0.0–9.4.4, 9.5.0
Timeline
- 2026-08-13: disclosed
- 2026-08-13: patched: Fixes released in Kibana 8.19.20, 9.4.5, 9.5.1