Impact
A confused‑deputy flaw in Kibana allows a lower‑privileged user to invoke functionality that operates with another user's privileges. This programming error means that data from sources the user is not authorized to access can be processed and returned, resulting in unauthorized disclosure of protected information.
Affected Systems
Elastic Kibana is affected. The CVE data does not provide specific affected release versions.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while an EPSS score of less than 1 % shows a very low probability of exploitation. The vulnerability is not listed in CISA KEV and no public exploits are documented. The attack requires an authenticated user with basic access to the Kibana interface or API who can trigger the unprotected call that forwards another user's identity. Because it is a privilege‑confusion issue rather than a remote code execution vector, practical risk is limited but still relevant for environments with sensitive data.
OpenCVE Enrichment