# Kibana 9.4.8, 9.5.5 Security Update (ESA-2026-193)

**URL:** <https://discuss.elastic.co/t/kibana-9-4-8-9-5-5-security-update-esa-2026-193/390866>\
**Category:** Security Announcements\
**Created:** [October 6, 2026, 6:44pm UTC](https://discuss.elastic.co/t/kibana-9-4-8-9-5-5-security-update-esa-2026-193/390866 "2026-10-06T18:44:15Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cronosda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cronosda/32/147882_2.png) [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Post date:** [October 6, 2026, 6:44pm UTC](https://discuss.elastic.co/t/kibana-9-4-8-9-5-5-security-update-esa-2026-193/390866/1 "2026-10-06T18:44:15Z")

</div>

**Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure**

Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensitive credential material that should be restricted to users with Fleet settings administrative access. Successful exploitation could allow an attacker to obtain private cryptographic key material configured for Fleet Server host connections, potentially enabling impersonation of trusted Fleet infrastructure components in deployments where those keys are actively used.

**Affected Versions:**

> - 9.x:

- All versions from 9.3.0 up to and including 9.3.8
- All versions from 9.4.0 up to and including 9.4.7
- All versions from 9.5.0 up to and including 9.5.4

No fix is available for the 9.3.x line, which is no longer maintained. Users on 9.3.x should upgrade to a supported release line.

Users on the 8.x release line are not affected. The Fleet Server host SSL private key functionality that contains this vulnerability was introduced after the 8.x release line and is not present in 8.19.x.

**Affected Configurations:**

> - Kibana deployments using Fleet where Fleet Server hosts are configured with SSL/TLS private key material stored in Fleet settings. Deployments that do not configure Fleet Server hosts with private key material in Fleet settings are not exposed to this vulnerability.

**Solutions and Mitigations:**

The issue is resolved in Kibana 9.4.8 and 9.5.5.

The versions above are the first releases that contain the fix, and later releases also contain it. Elastic recommends upgrading to the most recent release available, and reviewing the [known issues](https://www.elastic.co/docs/release-notes) for your target version before upgrading.

**For Users that Cannot Upgrade:**

> - **Self-hosted and Cloud:** Administrators can mitigate this vulnerability by removing the Fleet agent management feature privilege from any Kibana role assigned to users who should not have access to Fleet Server host configuration data. Users who require Fleet agent operations but not Fleet settings visibility should not be granted the Fleet _agents\_all_ Kibana feature privilege unless they also hold Fleet settings read access.

**Indicators of Compromise (IOC)**

No specific indicators of compromise have been identified for this vulnerability.

**Elastic Cloud Serverless**

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

**Severity:** CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N  
**CVE ID:** CVE-2026-102412  
**Problem Type:** CWE-863 - Incorrect Authorization  
**Impact:** CAPEC-1 - Accessing Functionality Not Properly Constrained by ACLs
