{"id":"CVE-2026-102412","summary":"Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure","details":"Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensitive credential material that should be restricted to users with Fleet settings administrative access. Successful exploitation could allow an attacker to obtain private cryptographic key material configured for Fleet Server host connections, potentially enabling impersonation of trusted Fleet infrastructure components in deployments where those keys are actively used.","modified":"2026-10-11T07:05:32.493779365Z","published":"2026-10-06T19:31:44.904Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102412.json","unresolved_ranges":[{"extracted_events":[{"introduced":"9.3.0"},{"last_affected":"9.3.8"},{"introduced":"9.4.0"},{"last_affected":"9.4.7"},{"introduced":"9.5.0"},{"last_affected":"9.5.4"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-9-4-8-9-5-5-security-update-esa-2026-193/390866"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102412.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102412"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"17b451d8979a29e31935fe1eb901310350b30e62"},{"last_affected":"171dd53e53c29b91f45d2d87857a3f74db48cca5"},{"introduced":"2e8528e92361c3399724226deaf2b46f933e925b"},{"fixed":"c042abbb0eaaaa61b49beef21d517468861a4db2"},{"introduced":"8d4246a64bc255212407b1b313fe402391299c88"},{"fixed":"48acba663b09e70b115dd879329141506c377890"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.3.0"},{"last_affected":"9.3.8"},{"introduced":"9.4.0"},{"fixed":"9.4.8"},{"introduced":"9.5.0"},{"fixed":"9.5.5"}],"source":"CPE_RANGE"}}],"versions":["v9.5.4","v9.4.7","v9.5.3","v9.4.6","v9.5.2","v9.5.1","v9.4.5","v9.5.0","v9.3.8","v9.4.4","v9.3.7","v9.4.3","v9.3.6","v9.4.2","v9.3.5","v9.4.1","v9.4.0","v9.3.4","v9.3.3","v9.3.2","v9.3.1","v9.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102412.json","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/48acba663b09e70b115dd879329141506c377890","target":{"file":"server/src/internalClusterTest/java/org/elasticsearch/index/shard/IndexShardIT.java"},"deprecated":false,"digest":{"line_hashes":["90954522904478845627767809963626966632","312202333282412865980452074165561988045","201502984854532540743675824692178650491","133021856339520246587832744823698128960","118567998432359533306447586005283286049","321063442713962830327798090638255728923","116674126915488887653231158661015327407","340129969494685833618437681997224425313","135673196400076405753847860598907169645","122311869659862480733078545751265298438","252396072946849092724372221039036583896","135357956602451340512845621008925333259","91393826567900247708322597243985039115","257536988596658647353060035863545299747","635876167132524114432519423301563958","211976191649846492472867523364748761608","301472925400710851361978247629893735954","178249879224873702898662621420154824388","203141962289939396495271583042215390544"],"threshold":0.9},"id":"CVE-2026-102412-903e63cd"},{"target":{"function":"testNodeWriteLoadsArePresent","file":"server/src/internalClusterTest/java/org/elasticsearch/index/shard/IndexShardIT.java"},"deprecated":false,"digest":{"length":797,"function_hash":"139800561303427826632305893219156980695"},"id":"CVE-2026-102412-9f3d66c3","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/48acba663b09e70b115dd879329141506c377890"},{"source":"https://github.com/elastic/elasticsearch/commit/c042abbb0eaaaa61b49beef21d517468861a4db2","target":{"file":"server/src/internalClusterTest/java/org/elasticsearch/index/shard/IndexShardIT.java"},"deprecated":false,"digest":{"line_hashes":["90954522904478845627767809963626966632","312202333282412865980452074165561988045","201502984854532540743675824692178650491","133021856339520246587832744823698128960","118567998432359533306447586005283286049","321063442713962830327798090638255728923","116674126915488887653231158661015327407","340129969494685833618437681997224425313","135673196400076405753847860598907169645","122311869659862480733078545751265298438","252396072946849092724372221039036583896","135357956602451340512845621008925333259","91393826567900247708322597243985039115","257536988596658647353060035863545299747","635876167132524114432519423301563958","211976191649846492472867523364748761608","301472925400710851361978247629893735954","178249879224873702898662621420154824388","203141962289939396495271583042215390544"],"threshold":0.9},"id":"CVE-2026-102412-a1e3c91c","signature_type":"Line","signature_version":"v1"},{"id":"CVE-2026-102412-a4a25bad","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/c042abbb0eaaaa61b49beef21d517468861a4db2","target":{"file":"server/src/internalClusterTest/java/org/elasticsearch/index/shard/IndexShardIT.java","function":"testNodeWriteLoadsArePresent"},"deprecated":false,"digest":{"function_hash":"139800561303427826632305893219156980695","length":797}}],"vanir_signatures_modified":"2026-10-11T07:05:32Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"30ab63cc0017fe2da7a84fb9b285dd762468802d"},{"last_affected":"e39c92c646f9a6b1e4b7b68d9f59967bb77d5732"},{"introduced":"b2e39752e03b56f48f51943214475ddba1f8e974"},{"fixed":"e480f260be8f73cfb3424961a59867631291a2dd"},{"introduced":"240f7d17d21408117f4295bcf74d48092ab0d078"},{"fixed":"a2890159e2486503b9e3a0c6f422b153a746651a"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.3.0"},{"last_affected":"9.3.8"},{"introduced":"9.4.0"},{"fixed":"9.4.8"},{"introduced":"9.5.0"},{"fixed":"9.5.5"}],"source":"CPE_RANGE"}}],"versions":["v9.5.4","v9.4.7","v9.5.3","v9.4.6","v9.5.2","v9.5.1","v9.4.5","v9.5.0","v9.3.8","v9.4.4","v9.3.7","v9.4.3","v9.3.6","v9.4.2","v9.3.5","v9.4.1","v9.3.4","v9.4.0","v9.3.3","v9.3.2","v9.3.1","v9.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102412.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}