Impact
Missing Authorization (CWE-862) in an internal Kibana data retrieval capability allows an authenticated low‑privileged user to read endpoint response action records and the content returned by managed hosts. The vulnerability arises because the functionality does not enforce the same Security Solution and endpoint privileges that its user‑facing counterparts do, effectively elevating the privileges of the internal request. This can lead to a confidentiality compromise where sensitive host response data is exposed to unauthorized users.
Affected Systems
Kibana from Elastic is affected. The vulnerability exists in deployments that utilize the Elastic Defend endpoint response actions, and the specific version impact is not listed, so all current Kibana releases should be considered potentially vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that known exploitation is unlikely but cannot be ruled out. Local authentication is required to exploit the flaw, meaning a low‑privileged user account that has access to Kibana can trigger the disclosure. The official reference points to a security update that mitigates the issue, implying that the vulnerability is actively tracked by Elastic.
OpenCVE Enrichment