Impact
Cross‑Site Request Forgery in Kibana allows an attacker who has permission to create visualizations to embed a malicious Vega chart that, when other users view it, causes Kibana to make authenticated requests on their behalf. This can lead to unauthorized operations or elevation of privileges if the victim has higher rights than the attacker.
Affected Systems
The vulnerability affects Elastic Kibana, specifically any deployed versions that support user‑created Vega visualizations. Version information is not provided, but the issue applies to all releases where the described functionality exists.
Risk and Exploitability
The CVSS score of 7.3 indicates a moderate‑to‑high risk, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. Exploitation requires the attacker to create a malicious viz owned by an authorized user and persuade another user to view it; no network‑level attack is required, making the attack vector rely on social engineering and legitimate user interactions.
OpenCVE Enrichment