CVE-2026-33461 is an incorrect authorization vulnerability in Kibana that allows users with limited Fleet privileges to exploit an internal API endpoint and retrieve sensitive configuration data, including private keys and authentication tokens, that should only be accessible to administrators. The vulnerability stems from inadequate authorization checks in the endpoint, which directly returns full configuration objects without enforcing the same restrictions applied by dedicated settings APIs. The vulnerability carries a CVSS score of 6.5 (Medium), indicating moderate severity. It requires network access and low-level user privileges to exploit, with no user interaction needed. The attack has high confidentiality impact, exposing sensitive authentication credentials and configuration details, though it does not affect system integrity or availability. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is readily available. Community attention appears minimal given the low EPSS score of 0.0006, suggesting the threat landscape interest is relatively low at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.19.14CPE matchmatch criteria | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.2.8CPE matchmatch criteria | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | ||
>= 9.3.0, < 9.3.3CPE matchmatch criteria | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.19.13CPE match | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.2.7CPE match | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.