云虫漏洞库

CVE-2026-72632 - Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents i - 漏洞详情

漏洞编号:CVE-2026-72632

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-72632

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-203

发布/更新时间:2026-08-13 / 2026-08-28

漏洞描述

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests.

相关链接

相关漏洞

« 返回首页