#VU125547 Execution with unnecessary privileges in Kibana - CVE-2026-4498
Published: April 9, 2026
Kibana
Elastic Stack
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to execution with unnecessary privileges in Kibana Fleet plugin debug route handlers when handling requests to internal debug routes. A remote user can send requests to the debug routes to disclose sensitive information.
Exploitation requires Fleet to be enabled and the user to have Fleet sub-feature privileges such as agents, agent policies, or settings management.