Impact
Fleet Server is vulnerable to code injection (CWE‑94) because Kibana accepts an output‑configuration identifier without sanitizing it. The identifier is later embedded into a server‑side script that Fleet Server builds during routine agent‑policy processing, allowing an attacker’s script content to be executed as code rather than treated as data. This flaw can be used to run arbitrary code with the privileges of the Fleet Server process, potentially compromising data confidentiality, integrity, and availability on the affected host.
Affected Systems
Elastic Fleet Server is affected. The vulnerability exists in versions prior to the security update referenced in the discussion thread (Fleet Server 8.19.20, 9.4.5, and 9.5.1). Systems running earlier or unpatched releases of the product should be considered vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate level of severity. The exploit requires that an attacker have the ability to create or modify an output‑configuration identifier in Kibana, which may imply authenticated or privileged access. Since no EPSS value is available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of an immediate, widespread exploitation is currently low, but the potential impact of successful code execution is significant.
OpenCVE Enrichment