Impact
The vulnerability is an Authorization Bypass Through User‑Controlled Key, allowing a user to bypass ACL checks and access features in Kibana that belong to a different space. This leads to disclosure of inference output from a trained model that the user is not authorized to view, exposing the model’s behavior. The same flaw also permits stopping or altering an active model deployment in another space, effectively disrupting that service.
Affected Systems
The affected vendor is Elastic; the product is Kibana. No specific version information was provided in the data, so all releases of Kibana may be impacted until a fix is issued.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, via the Kibana web interface, but the exact prerequisites are not detailed in the description. Given the potential for cross‑space data disclosure and domain disruption, the risk remains significant.
OpenCVE Enrichment