Loading
Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (such as agents, agent policies, and settings management).
Use CWE-250, Elastic vendor hub and Kibana product page to widen CVE-2026-4498 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-26938, CVE-2026-33461 and CVE-2026-33459 for nearby disclosures in the same product family.