Impact
The vulnerability is a missing authorization flaw that allows a user with limited privileges in Kibana to access workflow execution outputs that should be restricted. The likely attack vector is via the publicly documented API. By using the publicly documented API, an attacker can retrieve data such as responses from connected data sources, including potentially sensitive information that the caller would not normally be able to see. This flaw does not provide arbitrary code execution or other high‑impact exploits but does leak confidential data that could undermine confidentiality and compromise internal processes.
Affected Systems
The flaw affects Elastic Kibana installations. No specific major or minor version range is listed in the CVE data; however, the Elastic security discussion referenced in the advisory indicates that remediation is available in recent releases. Users should verify which Kibana version they run and determine if they have applied the patch updates outlined by Elastic.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, further implying that active exploitation is not confirmed. Based on the description, it is inferred that the attack path requires authentic access to the Kibana instance via the documented API; an attacker would need at least normal user privileges within a Kibana space to exploit the flaw. The disclosed data could lead to significant confidentiality loss but does not affect availability or integrity.
OpenCVE Enrichment