Impact
This vulnerability is a missing authorization flaw (CWE-862) in Kibana that allows a user with permission to author and evaluate Elastic Security detection rules to trigger Osquery and Elastic Defend response actions on enrolled hosts without possessing the normally required Osquery live query or Elastic Defend privileges. The unauthorized execution can disclose host information or cause unauthorized changes to host state.
Affected Systems
Elastic Kibana is affected. Specific product versions are not listed in the available data, so all deployed instances of Kibana should be reviewed for exposure. The absence of version details requires administrators to verify whether their installations fall within the scope of this flaw.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. EPSS is not available and the flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploit yet. The likely attack path involves the Kibana web interface and requires a user with rule authoring and evaluation rights, which the vendor had incorrectly assumed were sufficient to enforce all ACLs. Once a malicious or compromised rule is created, response actions can be executed against hosts, bypassing normal privilege checks.
OpenCVE Enrichment