Impact
Missing authorization in Kibana permits an authenticated user with Synthetics privileges scoped to a single space to delete Synthetics monitors that are shared into spaces the user otherwise cannot access, permanently removing those monitors. The same operation can also erase the underlying Elastic Agent integration configuration when the monitor is linked to a private location, bypassing the authorization checks normally performed by Fleet. The deficiency is a classic implementation of missing access control (CWE‑862).
Affected Systems
The vulnerability affects Elastic Kibana, although no specific versions are listed in the advisory. Any deployment that uses Synthetics monitors and allows cross‑space sharing of those monitors with users who have Synthetics privileges is potentially susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 signals a moderate severity level. EPSS data is not available and the vulnerability is not included in the CISA KEV catalog, so aggressive exploitation has not been documented. Nonetheless, the attack requires an authenticated user with Synthetics rights, implying that credential compromise or privilege escalation within the organization could enable exploitation. The impact would be loss of monitoring data and possible disruption of Fleet integrations.
OpenCVE Enrichment