Impact
Kibana’s Metrics Experience feature contains an internal API that lacks the required Kibana‑level authorization check. When an authenticated user possesses only data‑store‑read access to an index and does not hold the related Kibana privilege, they can call the unprotected endpoint and receive metric data derived from that index. This allows the disclosure of sensitive metric information that a properly protected API would otherwise hide. The weakness is classified as Missing Authorization (CWE‑862).
Affected Systems
The product affected is Elastic Kibana. The advisory does not list a specific vulnerable version; check the Elastic discussion thread linked in the references for the exact releases that contain the fix, and update accordingly.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires legitimate authentication within Kibana and data‑store‑read permissions. Attackers would simply send a request to the internal metrics endpoint, which is exposed only to Kibana internal traffic. There is no known code execution or denial‑of‑service impact, but the data disclosed can be valuable to an attacker.
OpenCVE Enrichment