Impact
A user with only read‑policy privileges in Kibana can access the entire Fleet proxy configuration, including authentication credentials and private keys. This reveals sensitive data that should be protected by higher‑level Fleet privileges, potentially allowing attackers to compromise downstream services that rely on those credentials.
Affected Systems
The vulnerability affects Elastic Kibana. No specific product version is listed in the available data; the CVE applies to the Kibana component wherever the described privilege model exists.
Risk and Exploitability
The CVSS score of 7.7 indicates a high risk of exposure; the EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be able to log in as a user with read‑policy rights, which is a relatively low barrier under many configurations. Once privilege is granted, the attacker can read the full Fleet proxy configuration and exfiltrate credentials and key material, leading to potential lateral movement or compromise of external systems. The lack of additional mitigations in the environment increases the likelihood of exploitation.
OpenCVE Enrichment