Impact
The vulnerability is a missing authorization flaw in Kibana’s Entity Store feature that allows an authenticated user with limited security capabilities to trigger an administrative operation. That operation creates and persists Elasticsearch API keys under the caller’s identity, effectively bypassing the elevated privileges normally required for the entity store setup flow. The result is that an attacker can generate new API keys without proper authorization, potentially gaining further access within the cluster.
Affected Systems
Elastic Kibana is affected. No specific version information is provided in the available data, so the issue may exist across multiple releases until a patch is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be an authenticated low‑privilege user exploiting the lack of proper ACL enforcement, making the exploitation highly dependent on the existence of such a user and the manner in which the entity store API is accessed.
OpenCVE Enrichment