Impact
Incorrect authorization in Kibana Fleet allows an authenticated user with only the Elastic Defend endpoint policy management privilege to convert an endpoint policy into a different integration policy, effectively bypassing restriction checks. The flaw resides in evaluating the policy against the stored integration rather than the new one supplied during an update, leading to privilege abuse (CAPEC‑122). The attacker can therefore gain unauthorized control over integration configurations, compromising confidentiality, integrity, and potentially availability of the system.
Affected Systems
The vulnerability affects Elastic’s Kibana product, specifically the Fleet component that manages integration policies. No specific product versions are listed in the CVE data, so all current installations of Kibana Fleet should be considered potentially affected.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity. No EPSS value is available, and the issue is not listed in CISA's KEV catalog. The attack requires a valid authenticated session with limited privileges, but once authenticated it can be exploited without additional access. The risk is moderate to high for installations that use Fleet, especially if users are granted the Elastic Defend policy management role.
OpenCVE Enrichment