← Back

CVE-2026-72670

nvd nist
Published: Aug 13, 2026Modified: Sep 4, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be authorized to view.

Affected (2)

Products: Elastic: Kibana
1 product
Kibana
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Elastic
Before 8.19.20
From 9.0.0 to 9.4.5

Timeline

No history available yet.