Impact
The vulnerability is an authorization bypass that allows a user who can run Osquery live queries in one Kibana space to trigger a query on Elastic Agents assigned to a different space. The attacker can request a query using a user-controlled key, which is not properly constrained by ACLs. The executed query returns host data to the Osquery results stream, resulting in disclosure of sensitive information. The weakness is classified as CWE‑639, a typical privilege escalation flaw that can be exploited by an authenticated user.
Affected Systems
This flaw affects Elastic Kibana installations. Any deployment where users have permissions to run Osquery live queries in a space and where agents are assigned to other spaces is potentially vulnerable. The data provided does not identify a specific version, so all deployed instances are considered at risk until the official fix is applied.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with query privileges in one space and the ability to craft an OS query key. No additional system compromise is required to achieve the data disclosure.
OpenCVE Enrichment