Threats Tagged 'bit-elk-2026-72632'
View all threats tagged with 'bit-elk-2026-72632'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bit-elk-2026-72632'
Click on any threat for detailed analysis and mitigation recommendations
Elk: Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API Keys (CVE-2026-72632)CVE-2026-72632 0 A vulnerability in Kibana Fleet allows an attacker to reconstruct Elasticsearch API keys of enrolled Elastic Agents via a side-channel attack. The flaw arises because Fleet removes API key values from agent listing responses but accepts caller-supplied filter expressions evaluated with elevated privileges. By observing the number of matching agents for crafted filters, an attacker can infer the API key characters one at a time. Join the discussion | GCVE Database | 08/19/2026, 08:40:21 UTC Added: 08/19/2026, 13:50:34 UTC |
CVE-2026-72632: CWE-203 Observable Discrepancy in Elastic KibanaCVE-2026-72632 0 Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests. Join the discussion | CVE Database V5 | 08/19/2026, 08:40:21 UTC Added: 08/13/2026, 19:26:55 UTC |
Showing 1 to 2 of 2 results