---
cve: "CVE-2026-4498"
severity: "HIGH"
cvss: 7.7
epss: "0.3%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-04-08 17:21:24"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-26T10:15:51+02:00"
---

# CVE-2026-4498

> 7.7 HIGH

## Beschreibung

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (such as agents, agent policies, and settings management).

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-250** — Execution with Unnecessary Privileges
  The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

## Angriffsmuster (CAPEC)

- [CAPEC-69 — Target Programs with Elevated Privileges](https://capec.mitre.org/data/definitions/69.html) _(Severity: Very High)_
- [CAPEC-104 — Cross Zone Scripting](https://capec.mitre.org/data/definitions/104.html) _(Severity: High)_
- [CAPEC-470 — Expanding Control over the Operating System from the Database](https://capec.mitre.org/data/definitions/470.html) _(Severity: Very High)_

## Patch verfügbar (OSV)

- f9adf4c29021dbda28cae7d9c11924471798723d (Commit)
- cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1 (Commit)

## Referenzen

- <https://discuss.elastic.co/t/kibana-8-19-14-9-2-8-9-3-3-security-update-esa-2026-21/385811>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-4498) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
