Impact
A flaw in the authorization logic of Kibana allows an authenticated user with only read‑only access within a Kibana space to discover and alter entity store maintainer tasks. By toggling these tasks the user can silently disable the automated Entity Analytics maintenance, leading to loss of data analysis capabilities and potential data inconsistencies without the data owners’ knowledge. The weakness is a classic authorization bypass (CWE‑863).
Affected Systems
The vulnerability affects Elastic’s Kibana product. Users running any version of Kibana that has not been hardened to this update are potentially impacted; the advisory at the provided link confirms that the issue existed in releases prior to the listed security update.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently known to be actively exploited in the wild. The attack requires a valid account with read access in a Kibana space; it can be performed without additional network-level privileges, making the exploit relatively straightforward for anyone who has legitimate Kibana credentials. Because the effect is the inadvertent disabling of analytics maintenance, the impact is primarily a loss of functional integrity rather than a direct confidentiality or availability breach. The lack of a publicly available exploit does not eliminate the risk, however; an attacker controlling a read‑only user could mount automated scans to find vulnerable spaces and modify resources as described.
OpenCVE Enrichment