Impact
The vulnerability in Kibana's Cribl integration permits an authenticated user with Fleet management privileges to inject attacker-controlled expressions into a server-side script template. This injection creates an Elasticsearch ingest pipeline that can be written outside the caller’s authorized permissions, effectively allowing the user to elevate privileges on the Elasticsearch cluster.
Affected Systems
The affected product is Elastic Kibana. No specific version ranges are listed in the CVE entry, so the risk applies to any installation that includes the vulnerable Cribl integration. The Elastic discussion link references updates for versions 8.19.21, 9.4.6, and 9.5.3, which contain the fix.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity, and there is no EPSS data available. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with Fleet management rights, so the attack vector is internal and necessitates access to Kibana. Once exploited, the attacker can write ingest pipelines beyond their normal permissions, giving them indirect control over data indexing and potential data tampering.
OpenCVE Enrichment