Information disclosure in Kibana - CVE-2026-72670
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Fleet proxy configuration when reading agent policies. A remote user can read the entire configuration of a configured Fleet proxy to disclose sensitive information.
Only instances with at least one Fleet proxy configured with credentials are vulnerable.