Executive brief
Kibana is Elastic's data visualization and exploration platform used to analyze logs and metrics from the Elastic Stack. A missing authorization flaw in the Fleet feature allows an authenticated user with read-level permissions in one workspace to view agent metadata and diagnostic information belonging to agents in other workspaces, violating data isolation boundaries. This could expose operational details about infrastructure managed by other teams or projects.
Technical details
The vulnerability is a missing authorization check (CWE-862) in Kibana's Fleet plugin that fails to properly enforce space-level access controls. An authenticated user holding read-level Fleet agent privileges in one Kibana space can enumerate and access agent metadata and diagnostic content from agents in other spaces, bypassing intended isolation. The attack requires network access and prior authentication, with no user interaction needed. The flaw affects Kibana 9.x versions 9.1.0–9.4.5 and 9.5.0–9.5.2 when Fleet space awareness is enabled (default in new 9.x installations); it is resolved in versions 9.4.6 and 9.5.3.
Affected products
- Elastic Kibana 9.1.0 to 9.4.5, 9.5.0 to 9.5.2
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Fixed in Kibana 9.4.6 and 9.5.3