Impact
Incorrect authorization controls in Kibana allow tactical manipulation of integration package configuration data to impersonate high‑privilege agents. A user with Fleet management rights can alter the privilege declarations sent to Elasticsearch, causing all Elastic Agents on a selected policy to receive credentials that grant access to perform any action on the cluster, including full administrative control.
Affected Systems
The vulnerability affects Elastic Kibana instances. No specific version range is provided, but the issue is tied to the authorization logic used when minting credentials for Elastic Agents. Users should consider all Kibana releases before the documented security update as potentially impacted.
Risk and Exploitability
The CVSS score of 8.1 classifies this as a high‑severity flaw. EPSS data is unavailable, but the lack of any public record of exploitation and its inclusion in the KEV catalog is not noted. The attack vector requires an existing user with Fleet management privileges to modify integration packages, after which all agents obtain escalated cluster privileges. This can lead to uncompromised cluster control by a determined internal actor.
OpenCVE Enrichment