Impact
The vulnerability is an incorrect authorization flaw that allows an authenticated user with only read‑level Security feature access in Kibana to stop the recurring Privilege Monitoring engine task for a space. When the engine task is disabled, no monitoring data is produced for that space, yet the engine continues to report a healthy state to operators. The result is a loss of visibility into privileged user activity, giving an attacker or insider a blind spot in which illicit actions may go undetected.
Affected Systems
The issue affects Elastic’s Kibana product. No specific affected version numbers are provided in the available data, so any deployment running the vulnerable component should be presumed at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attack requires an authenticated user within the Kibana environment with read‑level Security feature permissions but no Elasticsearch privileges. The attacker could use the legitimate UI to disable the monitoring engine; thus the attack vector is internal, relying on legitimate credentials. Once disabled, the engine reports a false healthy status, masking the loss of monitoring for operators.
OpenCVE Enrichment