CVE-2026-33461

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges can exploit an internal API endpoint to retrieve sensitive configuration data, including private keys and authentication tokens, that should only be accessible to users with higher-level settings privileges. The endpoint composes its response by fetching full configuration objects and returning them directly, bypassing the authorization checks enforced by the dedicated settings APIs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

22 Apr 2026, 16:44

Type Values Removed Values Added
CPE cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
References () https://discuss.elastic.co/t/kibana-8-19-14-9-2-8-9-3-3-security-update-esa-2026-24/385812 - () https://discuss.elastic.co/t/kibana-8-19-14-9-2-8-9-3-3-security-update-esa-2026-24/385812 - Vendor Advisory
First Time Elastic
Elastic kibana

08 Apr 2026, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 17:21

Updated : 2026-04-22 16:44


NVD link : CVE-2026-33461

Mitre link : CVE-2026-33461

CVE.ORG link : CVE-2026-33461


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-863

Incorrect Authorization