Impact
An authorization bypass (CWE‑639) in Kibana’s Fleet package installation allows a user with delegated package‑management rights to claim a data stream identifier already in use by another tenant. By not verifying ownership before applying the configuration, the tenant’s data stream can be redirected to infrastructure controlled by the attacker, exposing subsequent data to unauthorized disclosure, tampering, and preventing it from reaching its intended destination. The flaw can persist even after the malicious package is removed, requiring additional remediation of affected infrastructure.
Affected Systems
Elastic Kibana deployments that employ the Fleet package installation process are vulnerable. The affected product is Kibana by Elastic, with no specific version information provided in the advisory. Any instance where a user holds delegated Fleet package‑management privileges without full Elasticsearch administrative rights may be susceptible.
Risk and Exploitability
With a CVSS score of 8.8, this vulnerability is rated high severity, and its EPSS score is not available, so current exploitation probability is unknown. The flaw is not listed in the CISA KEV catalog. The likely attack vector is an internal actor leveraging legitimate delegated permissions to claim a data stream identifier. Successful exploitation could allow the attacker to intercept and, potentially, modify the data of another tenant, and the impact persists even if the malicious package is later removed, reflecting the need for careful infrastructure review.
OpenCVE Enrichment