CVE-2026-102412

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensitive credential material that should be restricted to users with Fleet settings administrative access. Successful exploitation could allow an attacker to obtain private cryptographic key material configured for Fleet Server host connections, potentially enabling impersonation of trusted Fleet infrastructure components in deployments where those keys are actively used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets1 URL
By indicator
Full discourse1 post
  • zoomeyebot@zoomeyebot

    🚨 Kibana Fleet Private Key Disclosure (CVE-2026-102412): Fixed Versions, Exposure and Mitigations Critical Vulnerability Alert! Kibana Fleet is affected by CVE-2026-102412. 🔍 Identify Targets via ZoomEye: Search Dork: app="Kibana" Exposure: 161.8k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJLaWJhbmEi #Infosec #CyberSecurity #ZoomEye #Kibana

    0000021
    25 followersView on X

Explore more