Impact
The CVE involves the Kibana Agent Builder A2A JSON‑RPC API. An authenticated user with only read privilege can supply a conversation identifier that is already in use by another user. Because the ownership check does not differentiate between a nonexistent conversation and one owned by a different user, the request replaces the targeted conversation and reassigns it to the requesting account. The original owner permanently loses access to the conversation and its message history. The attacker can modify a conversation without reading its content, resulting in loss of integrity and availability for the affected data, but no direct disclosure of confidential information occurs.
Affected Systems
Elastic Kibana. The vulnerability applies to the Agent Builder component of Kibana, and it impacts all users of the same Kibana space where the conversation ID collision can occur. Version information is unknown.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. The attack requires the attacker to be authenticated within Kibana and to have read privileges for the Agent Builder. An attacker can exploit the vulnerability by submitting a crafted request to the JSON‑RPC endpoint, bypassing ownership checks. While exploitation does not allow reading the overwritten conversation, it can cause loss of user data and trust issues for impacted accounts.
OpenCVE Enrichment