Impact
Missing authorization allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges by sending direct requests to endpoints that are not properly protected. The flaw enables attackers to change configuration and service settings that manage cloud connectivity, which is a privileged operation. This is a classic privilege‑escalation vulnerability described by CWE-862.
Affected Systems
Elastic Kibana is the affected product. The CVE payload does not specify a version range, so any Kibana deployment that has not applied a remedial update from Elastic may be susceptible.
Risk and Exploitability
The CVSS score of 6.3 denotes moderate severity, while the EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation can be carried out by any authenticated user with valid credentials or a compromised account; the attacker sends requests to Cloud Connect endpoints sufficient to modify configuration, effectively granting unauthorized privilege escalation.
OpenCVE Enrichment