Impact
The vulnerability is a direct object reference flaw (CWE‑639) that lets users supply arbitrary identifiers for scheduled query result data in Kibana Spaces, allowing them to view data they are not authorized to access. This results in the confidential disclosure of information stored in other spaces but does not directly impact data integrity or availability.
Affected Systems
Elastic Kibana is the affected product. The description does not specify exact version numbers; any Kibana deployment that has not applied the security update referenced in Elastic’s discussion forum should be considered vulnerable.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate impact, and the EPSS score is under 1%, suggesting a low likelihood of exploitation at present. The flaw is not listed in CISA’s KEV catalog, so no confirmed active attacks are known. The likely attack vector is sending crafted HTTP requests that include identifiers pointing to scheduled query results in spaces the requester is not authorized to see. Based on the description it is inferred that an attacker can perform the exploit remotely by interacting with the Kibana API, though the exact authentication requirements are not detailed in the provided data.
OpenCVE Enrichment