Observable discrepancy in Kibana - CVE-2026-72632

 

Observable discrepancy in Kibana - CVE-2026-72632

Published: August 13, 2026


Vulnerability identifier: #VU142353
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72632
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose Elastic Agent Elasticsearch API keys.

The vulnerability exists due to observable discrepancy in Kibana Fleet when evaluating caller-supplied filter expressions over stored API key fields. A remote user can send a short sequence of crafted requests to disclose Elastic Agent Elasticsearch API keys.

The issue arises because the agent listing capability reports the number of matching agents after evaluating the filters with Kibana's internal Elasticsearch privileges, allowing the API key value to be reconstructed one character at a time.


Affected software

Kibana

How to mitigate CVE-2026-72632

Install security update from vendor's website.

Kibana - addressed in versions 8.19.20, 9.4.5, 9.5.1

External References

Related Security Bulletins