Impact
Kibana Fleet accepts a Fleet Server host configuration identifier directly from a user and later incorporates that unmodified value into a deletion request. This relative path traversal flaw (CWE‑23) allows a malicious identifier containing traversal sequences to trigger the deletion of the specified resource and potentially related objects, such as users or other configuration elements. The consequence is loss of data, disruption of service, and a breach of confidentiality, integrity or availability of the affected system.
Affected Systems
The vulnerability is present in installations of Elastic Kibana. Security update notes linked in the advisory indicate that the flaw is addressed in releases 8.19.18+, 9.3.7+, and 9.4.4+. Prior releases that have not applied these updates remain vulnerable.
Risk and Exploitability
The CVSS score of 7.3 signals a high severity, and the EPSS score is not available. The flaw is not yet listed in the CISA KEV catalog, meaning no widespread exploitation has been observed. It is inferred from the description that the attack requires a user with write privileges to Fleet Server host configurations, as such a user can submit a crafted identifier that contains traversal sequences. Successful exploitation would delete only the target resource referenced in the deletion request, but the loss of such resources could cascade to other system components.
OpenCVE Enrichment