Impact
A path traversal flaw in the Kibana Fleet feature allows a low‑privileged user to supply an arbitrary pathname that bypasses directory restrictions, causing the application to delete resources it should not touch. The effect can include the removal of accounts that possess elevated privileges, leading to loss of critical data and potential service disruption.
Affected Systems
Elastic Kibana is affected. No specific product versions are listed in the advisory; updates mentioned in the discussion thread should be applied as soon as they become available.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.3, indicating a moderate risk. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. A non‑admin user can trigger the flaw by interacting with the Fleet interface, and the resulting deletion occurs in the context of a higher‑privileged action. The attack requires authenticated access to Kibana and the ability to send a crafted request to the Fleet endpoint, but no extensive pre‑conditions are described.
OpenCVE Enrichment