Observable discrepancy in Kibana - CVE-2026-72632
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to disclose Elastic Agent Elasticsearch API keys.
The vulnerability exists due to observable discrepancy in Kibana Fleet when evaluating caller-supplied filter expressions over stored API key fields. A remote user can send a short sequence of crafted requests to disclose Elastic Agent Elasticsearch API keys.
The issue arises because the agent listing capability reports the number of matching agents after evaluating the filters with Kibana's internal Elasticsearch privileges, allowing the API key value to be reconstructed one character at a time.