Kibana 9.4.8, 9.5.5 Security Update (ESA-2026-193)

Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure

Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensitive credential material that should be restricted to users with Fleet settings administrative access. Successful exploitation could allow an attacker to obtain private cryptographic key material configured for Fleet Server host connections, potentially enabling impersonation of trusted Fleet infrastructure components in deployments where those keys are actively used.

Affected Versions:

  • 9.x:
  • All versions from 9.3.0 up to and including 9.3.8
  • All versions from 9.4.0 up to and including 9.4.7
  • All versions from 9.5.0 up to and including 9.5.4

No fix is available for the 9.3.x line, which is no longer maintained. Users on 9.3.x should upgrade to a supported release line.

Users on the 8.x release line are not affected. The Fleet Server host SSL private key functionality that contains this vulnerability was introduced after the 8.x release line and is not present in 8.19.x.

Affected Configurations:

  • Kibana deployments using Fleet where Fleet Server hosts are configured with SSL/TLS private key material stored in Fleet settings. Deployments that do not configure Fleet Server hosts with private key material in Fleet settings are not exposed to this vulnerability.

Solutions and Mitigations:

The issue is resolved in Kibana 9.4.8 and 9.5.5.

The versions above are the first releases that contain the fix, and later releases also contain it. Elastic recommends upgrading to the most recent release available, and reviewing the known issues for your target version before upgrading.

For Users that Cannot Upgrade:

  • Self-hosted and Cloud: Administrators can mitigate this vulnerability by removing the Fleet agent management feature privilege from any Kibana role assigned to users who should not have access to Fleet Server host configuration data. Users who require Fleet agent operations but not Fleet settings visibility should not be granted the Fleet agents_all Kibana feature privilege unless they also hold Fleet settings read access.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE ID: CVE-2026-102412
Problem Type: CWE-863 - Incorrect Authorization
Impact: CAPEC-1 - Accessing Functionality Not Properly Constrained by ACLs