CVE-2026-78595: Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure
Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and access diagnostic content belonging to agents enrolled in other Kibana spaces.
Affected Software
Event History
Frequently Asked Questions
Who is able to exploit this issue?
An authenticated Kibana user with read-level Fleet agent privileges in at least one Kibana space could exploit it. No user interaction is required.
What information could be exposed?
The user could enumerate agent metadata and access diagnostic content for agents enrolled in other Kibana spaces.
Does exploiting this issue require access to the affected agents themselves?
The disclosed data is accessed through Kibana Fleet authorization bypass, using the user's existing Fleet agent read-level privileges in one space. The provided information does not indicate that direct access to the agents is required.