Threats Tagged 'cve-2026-72632'
View all threats tagged with 'cve-2026-72632'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-72632'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-72632: CWE-203 Observable Discrepancy in Elastic KibanaCVE-2026-72632 0 Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests. Join the discussion | CVE Database V5 | 08/13/2026, 19:14:00 UTC Added: 08/13/2026, 19:26:55 UTC |
Showing 1 to 1 of 1 result