Impact
Missing authorization in Kibana (CWE‑862) allows an authenticated user with Security read‑level access in one Kibana space to trigger entity analytics migration operations that perform privileged writes in all Kibana spaces. The result is an unauthorized modification of data beyond the user’s intended scope, undermining data integrity and potentially enabling further exploratory or destructive activity.
Affected Systems
Elastic Kibana is the affected product; specific versions are not listed in the advisory, so all deployments of Kibana are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, so current exploitation probability is unclear. Attackers must be authenticated, but the privilege abuse can be exploited by any user with read‑level access, making the attack path relatively straightforward once credentials are possessed.
OpenCVE Enrichment