Impact
Improper Access Control in Kibana allows a low‑privileged authenticated user with read‑only Security Solution access to perform write operations on the Entity Analytics Watchlist configuration, a capability that should be restricted to elevated users. The flaw can also enable that user to access data beyond their authorized scope, potentially exposing sensitive information. The underlying weakness corresponds to CWE‑863 (improper authorization) and is also described as a CWE‑284 (Improper Access Control).
Affected Systems
Elastic Kibana installations of any supported version are potentially vulnerable, as no specific version was identified in the advisory. The issue is documented for deployments where read‑only users retain write capabilities to watchlist data. Users should consult the Elastic Security Update references for more detailed guidance and to confirm which releases contain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating moderate severity, and an EPSS of less than 1 %, suggesting a low likelihood of exploitation at this time. It is not listed in the CISA KEV catalog. An attacker must first authenticate with a low‑privileged Kibana account and then exploit the improper permission check to alter watchlist entries or view restricted data. The attack is localized to Kibana and does not require remote, unauthenticated access, but the impact on integrity and confidentiality can be significant for organizations tracking sensitive analytics.
OpenCVE Enrichment