Impact
The vulnerability in Kibana allows an authenticated user with read access to alerting rule configurations in a single space to retrieve alerting rule execution telemetry for spaces they are not authorized to access. The disclosed telemetry contains rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters, exposing sensitive operational data. This flaw is due to a user‑controlled key that is not properly validated against access control lists and is classified as CWE‑639.
Affected Systems
Elastic Kibana is affected; the specific product is Kibana by Elastic. No version information is provided in the current data, so all released Kibana versions could be vulnerable until an official patch is released.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and no EPSS score is available, suggesting low likelihood of exploitation. The vulnerability is not listed in CISA KEV. An attacker needs only an authenticated account with limited privileges to exploit the flaw, allowing data leakage but not full system compromise. The primary risk is confidentiality for internal telemetry, which could assist attackers in mapping business processes or identifying configuration weaknesses.
OpenCVE Enrichment