Impact
The flaw is a path traversal weakness in the Kibana Fleet feature that allows a user with write access to Fleet Settings to specify a pathname that resolves to internal directories outside the intended scope. Executing such a path can delete privileged Kibana objects such as user accounts and organizational assets, thereby causing loss of critical data and authentication material. This vulnerability is classified as CWE‑22.
Affected Systems
Elastic Kibana. No specific version constraints are listed, but the issue affects any deployment that includes the Fleet feature as described in the advisory.
Risk and Exploitability
The CVSS score of 7.3 indicates a medium to high severity. Exploitation requires the attacker to have write permissions on Fleet Settings and to interact with the Fleet interface, making the attack vector likely internal or through authenticated access. The EPSS score is not available and the vulnerability is not listed in CISA KEV, yet the potential for unauthorized deletion of critical resources keeps the risk significant.
OpenCVE Enrichment