Impact
Improper input validation (CWE‑20) in Kibana allows an authenticated user to submit a specially crafted Fleet policy, and the lack of validation can trigger a denial of service that renders the Fleet agent, server, and policy management functionality unavailable.
Affected Systems
The flaw affects all Elastic Kibana deployments that host or use Fleet policies; specific version numbers are not disclosed, so administrators should verify whether their current Kibana and Fleet components run at a vulnerable state. The issue exists in any deployment that allows users with permission to create or edit Fleet policies.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity, while the EPSS estimate of less than 1 % indicates a very low probability of exploitation. The issue is not listed in the CISA KEV. The specific role is not identified, but it is inferred from the description that a successful exploitation results in loss of availability for the Fleet component, disrupting monitoring and compliance operations.
OpenCVE Enrichment