CVE-2026-4498Disclosure(elastic / kibana)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (such as agents, agent policies, and settings management).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kibana

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
kibana

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 2Mentions · 2026-04-13: 1Technical Details · 2026-04-08: 204-0804-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure2
2026-04-131
Disclosure1
Full discourse3 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Elastic ❗ CVE-2026-4498 ❗ CVE-2026-33466 ❗ CVE-2026-33461 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-elastic-2/ https://t.co/9mpmyikW4w

    Post summary

    The post lists three Elastic CVEs and directs readers to a CERT link for more information.

    00020123
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4498 Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope v… https://www.cve.org/CVERecord?id=CVE-2026-4498

    Post summary

    The tweet announces a vulnerability (CVE‑2026‑4498) in Kibana’s Fleet plugin, detailing its privilege‑escalation nature and potential data leakage, but provides no exploit or remediation information.

    00000114
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4498 Privilege Abuse in Kibana Fleet Plugin Debug Route Handlers Enables Unauthorized Index Data Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4498

    Post summary

    CVE-2026-4498 is a newly disclosed privilege‑escalation vulnerability in Kibana Fleet Plugin’s debug route handlers that permits unauthorized access to index data.

    0000031
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelastickibana---

Explore more