Impact
An incorrect authorization flaw (CWE‑863) in Kibana allows an authenticated user who has Synthetics write rights in a single space to delete a private location that is shared with other spaces. When the private location is removed, the shared configuration is lost and all monitors in every space that reference it are stopped. The loss of these monitors disables availability monitoring for those spaces and prevents stakeholders from detecting outages, harming service reliability.
Affected Systems
Elastic Kibana instances that include the Synthetics feature and provide write privileges to users are affected. All deployments containing the code path that implements the deletion logic are impacted; no specific version numbers are asserted in the CVE data.
Risk and Exploitability
The CVSS score of 5.4 classifies the flaw as moderate severity. EPSS is unavailable, so the estimated exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user with Synthetics write permission, which requires legitimate login credentials or a compromised account. Once exploited, the attacker can cause availability disruptions by disabling monitors across multiple spaces.
OpenCVE Enrichment