CVE-2026-33461

7.7

Elastic · Kibana

Elastic Kibana contains an incorrect authorization flaw allowing authenticated users with limited Fleet privileges to access sensitive configuration data via an internal API.

Executive summary

An authorization bypass vulnerability in Elastic Kibana, identified as CVE-2026-33461, allows authenticated users with low privileges to exfiltrate sensitive configuration data, including private keys.

Vulnerability

This is an incorrect authorization vulnerability (CWE-863) affecting an internal API endpoint in Kibana. Authenticated users with limited Fleet privileges can bypass intended security controls to retrieve full configuration objects that contain private keys and authentication tokens.

Business impact

The exploitation of this vulnerability poses a significant risk to organizational security, as the exposure of private keys and authentication tokens could lead to full compromise of downstream infrastructure. With a CVSS score of 7.7, this vulnerability is classified as High severity, reflecting the potential for unauthorized access to highly sensitive system credentials and subsequent lateral movement.

Remediation

Immediate Action: Upgrade to Kibana version 8.19.14, 9.2.8, or 9.3.3 as recommended in the Elastic security update ESA-2026-24.

Proactive Monitoring: Audit access logs for unusual requests directed at internal Fleet API endpoints, particularly those originating from accounts with limited privileges.

Compensating Controls: Implement strict network segmentation and ensure that access to Kibana management interfaces is limited to trusted administrative networks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential data disclosure, organizations should prioritize the deployment of the provided patches. Administrators must verify their current version of Kibana and perform the update immediately to prevent unauthorized access to sensitive configuration tokens and private keys.

More Elastic CVEs

Sources