---
id: CVE-2026-4498
title: >-
  Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug
  route handlers can lead reading index data beyond their direct Elasticsearch
  RBAC scope via Privilege Abuse (CAPEC-122)
summary: >-
  Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug
  route handlers can lead reading index data beyond their direct Elasticsearch
  RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated
  Kibana…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-250
vendor: elastic
product: kibana
affected:
  - 'kibana >= 8.0.0, < 8.19.14'
  - 'kibana >= 9.0.0, < 9.2.8'
  - 'kibana >= 9.3.0, < 9.3.3'
patched:
  - kibana 9.3.3
published: '2026-04-08'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4498'
references:
  - url: >-
      https://discuss.elastic.co/t/kibana-8-19-14-9-2-8-9-3-3-security-update-esa-2026-21/385811
    label: security@elastic.co
tags:
  - nvd
epss: 0.003
epssPercentile: 0.22854
ingestedAt: '2026-07-26T00:06:15.067Z'
---

## Overview

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (such as agents, agent policies, and settings management).

## Affected

- `kibana >= 8.0.0, < 8.19.14`
- `kibana >= 9.0.0, < 9.2.8`
- `kibana >= 9.3.0, < 9.3.3`

## Remediation

Upgrade past the affected range:

- `kibana 9.3.3`
