#VU125548 Incorrect authorization in Kibana - CVE-2026-33461
Published: April 9, 2026
Kibana
Elastic Stack
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in an internal Fleet API endpoint when handling requests for configuration data. A remote user can send a request to retrieve sensitive configuration data to disclose sensitive information.
Exploitation requires Fleet to be enabled and the user to have Fleet Agents privilege without Fleet Settings privilege.