Impact
The vulnerability arises from an inconsistency in Kibana's file access authorization logic where the authorization check and the resource retrieval use distinct resolution mechanisms. This flaw, identified as CWE‑639, allows a low‑privileged authenticated user to read, modify, and delete case attachments that belong to feature areas they are not authorized to access. Consequently, an attacker can obtain the contents of protected case attachments, such as those linked to Security Solution cases, or alter and delete them, compromising confidentiality and integrity of sensitive data.
Affected Systems
The vulnerability affects the Elastic Kibana product. Specific versions are not listed; however, the advisory references the security update for Kibana 8.19.18‑9.3‑7‑9‑4‑3, implying earlier releases of that major line are impacted. Without version details, all installations of Kibana before the referenced patch should be considered vulnerable until proven otherwise.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as a high‑severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An authenticated attacker with limited file‑management privileges is the required vector; no special network or remote conditions are specified. If such an attacker gains access, they can abuse the mismatch between access checks and resource retrieval to bypass authorization controls.
OpenCVE Enrichment