Impact
An incorrect authorization check in Kibana allows an authenticated user with limited Fleet management privileges to access data that should be restricted to users with administrative access to Fleet settings. This flaw can expose private cryptographic key material used for Fleet Server host connections, creating the possibility for an attacker to impersonate trusted Fleet infrastructure components. The vulnerability is classified as CWE‑863 and can lead to a significant compromise of confidentiality for sensitive operational assets.
Affected Systems
Elastic Kibana is affected. The CVE description does not specify an affected version range; users should verify that their deployment runs a version prior to the published security update and consider upgrading if necessary.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, so the current exploitation likelihood is unknown. This issue is not listed in the CISA KEV catalog. The likely attack requires an authenticated Kibana session and may be carried out by an insider or an attacker who has compromised a user account with limited Fleet privileges. Successful exploitation could allow the attacker to read sensitive credential material and potentially impersonate Fleet services in affected deployments.
OpenCVE Enrichment