Impact
An authorization flaw (CWE-863) in Elastic's Kibana allows a low-privileged authenticated user to access response-action data they should not see. The flaw arises when the endpoint that returns action data is not properly constrained by ACLs, leading to the disclosure of potentially confidential control information. This vulnerability permits unauthorized information disclosure through the improper enforcement of access controls (CAPEC-1).
Affected Systems
All installations of Elastic Kibana that expose the vulnerable endpoint could be affected. The advisory does not list specific release numbers, so administrators should check the installed Kibana version against vendor documentation and confirm whether the environment meets the conditions described in the advisory.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. An EPSS score of less than 1% indicates a very low likelihood of exploitation at this time, and the vulnerability is not yet listed in the CISA KEV catalog. Because an attacker must first be authenticated with a low-privilege account, the attack path is limited; however, once authenticated the exploit is straightforward and results in the disclosure of otherwise protected action data.
OpenCVE Enrichment