Incorrect authorization in Kibana - CVE-2026-82299
Published: September 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in Fleet debugging interfaces when exploiting incorrectly configured access control security levels. A remote user can access exposed debugging interfaces to disclose sensitive information.
Only configurations with Fleet debugging interfaces enabled are vulnerable.