Impact
Elastic Kibana suffers from an incorrect authorization flaw that allows a user with workflow edit permissions to execute scheduled workflow tasks under the identity of a higher‑privileged user. By triggering the workflow, the attacker can read or modify data beyond the scope of their own access, effectively bypassing authorization limits. This issue is classified as CWE‑863, Incorrect Authorization.
Affected Systems
The affected product is Elastic Kibana. No specific version numbers are listed in the CNA data, so all installations of Kibana should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity. The EPSS score is not available, so the probability of exploitation cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be intra‑network or internal, requiring an authenticated session with workflow edit rights. Once the attacker has such a session, they can trigger a scheduled workflow to run under another user’s privileges, allowing them to gain unauthorized access to data and functions.
OpenCVE Enrichment