Impact
The vulnerability is an authorization bypass through a user‑controlled key that allows an authenticated user with the Timeline feature privilege in a Kibana space to enumerate, read, modify, and delete draft Timeline objects belonging to other users. Read access alone is sufficient for discovery and disclosure, while write access lets the attacker alter or delete the data. This elevates the user's effective permissions beyond what their role intends, exposing sensitive data and disrupting user workflows.
Affected Systems
Elastic’s Kibana product is affected, specifically any instance where users are granted Timeline feature privileges within a space. The vulnerability arises when ACL restrictions around timeline object access are not properly enforced, regardless of the specific Kibana version present. Affected deployments include all configurations that enable the Timeline feature and provide users with read or write access within shared spaces. The specific Kibana version affected is unknown or not disclosed.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate impact level. EPSS is not available, so the exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation at this time. However, the likely attack vector involves an authenticated user exploiting their legitimate access to the Timeline feature; enumeration and disclosure are possible with read privileges, while modification and deletion require write privileges. Because the flaw stems from an improperly constrained ACL, users with even minimal permissions can gain more control than intended.
OpenCVE Enrichment