CVE-2026-4498: Elastic Kibana
High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (such as agents, agent policies, and settings management).
Affected products
- Elastic Kibana: from 8.0.0, before 8.19.14 (fixed in 8.19.14); from 9.0.0, before 9.2.8 (fixed in 9.2.8); from 9.3.0, before 9.3.3 (fixed in 9.3.3)
Published 2026-04-08. Last modified 2026-07-25.