LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-72632

elastic · kibana

Published
CVSS7.1
Severityhigh
WeaknessCWE-203
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence o

References

← Back to the CVE Tracker

Our coverage of CVE-2026-72632

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-72632.