Impact
A mis‑implementation of authorization controls in Elasticsearch, identified as CWE‑863, allows an administrator to delegate a privileged role that is intended to be restricted to specific indices. The enforcement of index scoping during delegation fails to consider a role‑definition setting that can expand the matched index set. Consequently, a user holding this delegated privilege can modify their assigned role to gain access to additional indices that should remain protected, potentially including internal security data. This flaw enables an attacker to increase their privileges incrementally up to full administrative control of the cluster.
Affected Systems
The vulnerability affects Elasticsearch implementations. Security updates that address this issue are available in release branches 8.19.22, 9.4.7, and 9.5.4. All earlier releases that did not incorporate the patch are susceptible.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. While an EPSS score is not available, the lack of inclusion in the CISA KEV catalog suggests limited known active exploitation. The flaw is likely exploitable via the cluster’s internal REST API or via any interface that allows an administrator to modify role definitions, such as Kibana management console or direct role API calls. An attacker who can gain the delegated privilege can adjust role assignments to access restricted data and progressively increase privileges.
OpenCVE Enrichment