Executive brief
Kibana, an analytics and visualization platform used for monitoring application performance and infrastructure logs, contained a flaw that allowed any logged-in user to read sensitive APM server credentials. These credentials should only be accessible to administrators managing APM integrations. An attacker with basic Kibana access could obtain these secrets and use them to access the APM infrastructure, potentially exposing monitoring data and operational intelligence.
Technical details
A missing authorization check (CWE-862) in an internal Kibana APM integration function failed to validate user privileges before exposing APM server credentials. The vulnerability affects only Kibana deployments where Fleet-managed APM or cloud APM standalone configurations use secret token authentication; deployments without these features are not affected. An authenticated Kibana user can call the exposed function to read APM credentials that should be restricted to APM or Fleet administrators. The attacker requires network access to Kibana and valid authentication credentials but no special privileges. The issue is resolved in Kibana 8.19.21, 9.4.6, and 9.5.2; Elastic recommends rotating APM secret tokens after patching.
Affected products
- Elastic Kibana 7.14.0–7.17.29, 8.0.0–8.19.20, 9.0.0–9.4.5, 9.5.0–9.5.1
Timeline
- 2026-09-01: disclosed: Advisory published by Elastic (ESA-2026-144)
- 2026-09-01: patched: Fixes released in Kibana 8.19.21, 9.4.6, 9.5.2