Impact
Missing Authorization (CWE-862) in Kibana allows a user who can author detection rules to attach and trigger automated endpoint response actions without having the dedicated privileges that normally control those actions. The vulnerability enables the execution of commands such as host isolation, process termination, and arbitrary process execution on managed hosts whenever the associated detection rule generates an alert. Consequently, an attacker with only rule‑authoring rights can covertly cause damage or disrupt services on endpoints by leveraging the endpoint response feature.
Affected Systems
The issue applies to installations of Elastic Kibana that include the Elastic Security module. No specific product versions are listed, so all deployed Kibana instances with the security solution enabled are potentially affected until a corrected release is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score is currently not available, while the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via Kibana’s web interface, accessible to users with rule‑authoring privileges; it can be exploited by an insider or a compromised privileged account. Because the vulnerability directly bypasses endpoint privilege checks, it carries a moderate risk of confidentiality, integrity, and availability compromise, especially in environments where detection rule authors exist without corresponding endpoint privileges.
OpenCVE Enrichment