Impact
The vulnerability is an instance of Improper Input Validation (CWE-20) in Elastic Kibana that allows an authenticated user to submit a specially crafted Fleet policy. The lack of validation can lead to a denial of service, rendering the Fleet agent, server, and policy management features unavailable. The attack can be carried out simply by creating or editing a policy through the Kibana interface without further privileges beyond normal Fleet policy authorship. The resulting loss of availability undermines monitoring, logging, and compliance workflows that rely on Fleet.
Affected Systems
The flaw affects Elastic Kibana and its integrated Fleet components. Specific version numbers are not disclosed in the advisory, so administrators should verify whether their current Kibana and Fleet installations are running a vulnerable state. The problem exists in deployments that allow policy creation and editing via Kibana and do not enforce proper input validation on the received policy data.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity, while the EPSS estimate of less than 1 % indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need authenticated access to Fleet policy creation and editing functions; once achieved, they can trigger a denial of service against Fleet components, disrupting monitoring and compliance operations.
OpenCVE Enrichment