Kibana 8.19.20 and 9.4.5 Security Update (ESA-2026-87)

Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be authorized to view.

Affected Versions:

  • All versions up to and including 8.19.19
  • All versions from 9.0.0 up to and including 9.4.4

Affected Configurations:

  • At least one Fleet proxy is configured with credentials

Solutions and Mitigations:

The issue is resolved in versions 8.19.20 and 9.4.5.

For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: High ( 7.7 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE ID: CVE-2026-72670
Problem Type: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor