Impact
Missing authorization in the Kibana Fleet plugin allows an authenticated user with read‑level rights in one space to enumerate and read agent metadata and diagnostic data from agents located in other Kibana spaces. This cross‑space disclosure exposes potentially sensitive agent details and logs. The vulnerability is a classic case of insufficient access control (CWE‑862).
Affected Systems
Elastic Kibana, specifically the Fleet feature used for managing agents. The CVE does not state exact version numbers; any deployment that has not applied the corrective update is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and EPSS data is not available. The attack requires authentication and the user must hold Fleet read privileges; no additional network reachability is necessary beyond normal Kibana access. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet, but it could enable an attacker to harvest agent diagnostics and metadata, potentially aiding further reconnaissance or targeted attacks.
OpenCVE Enrichment