Impact
An authorization flaw (CWE‑862) in Kibana lets an attacker supply crafted input that bypasses space‑level access controls, enabling them to view data from other spaces. The resulting data leak can expose configuration details, logs, and potentially user information that should remain confidential.
Affected Systems
All deployments of Elastic Kibana that have not applied the security update described in the Elastic discussion forum. Specific product versions are not enumerated in the advisory, but the issue applies to any Kibana instance lacking the patch that enforces proper space‑level access restrictions.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. An EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via user‑supplied input to Kibana’s web interfaces or APIs, requiring network access to the Kibana cluster. The impact poses a risk of unauthorized disclosure of sensitive data to users who should not have access to other spaces.
OpenCVE Enrichment