---
cve: "CVE-2026-33460"
severity: "MEDIUM"
cvss: 4.3
epss: "0.2%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-04-08 16:43:30"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T20:03:44+02:00"
---

# CVE-2026-33460

> 4.3 MEDIUM

## Beschreibung

Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-122). A user with Fleet agent management privileges in one Kibana space can retrieve Fleet Server policy details from other spaces through an internal enrollment endpoint. The endpoint bypasses space-scoped access controls by using an unscoped internal client, returning operational identifiers, policy names, management state, and infrastructure linkage details from spaces the user is not authorized to access.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-863** — Incorrect Authorization
  The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

## Patch verfügbar (OSV)

- f9adf4c29021dbda28cae7d9c11924471798723d (Commit)
- cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1 (Commit)

## Referenzen

- <https://discuss.elastic.co/t/kibana-8-19-14-9-2-8-9-3-3-security-update-esa-2026-25/385813>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-33460) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
