Impact
The identified issue is a path traversal flaw in the Kibana Fleet feature that permits a low‑privileged user with write access to trigger an administrative delete operation on unintended internal resources. This weakness, classified as CWE‑22, effectively allows the attacker to delete data that should be protected by the application's directory restrictions. The vulnerability exploits the lack of proper pathname limitation and leverages the Fleet interface to conduct the deletion.
Affected Systems
The affected product is Elastic’s Kibana suite. No specific version numbers are provided in the advisory, so any Kibana installation that incorporates the Fleet feature and has not received the latest security update is potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability, and the EPSS score is not available, suggesting limited publicly known exploitation data. Because the exploit requires the administrator to interact with the Fleet interface, the attack vector is likely internal or requires compromised administrative credentials. The lack of listing in the CISA KEV catalog indicates no confirmed widespread exploitation to date, but the vulnerability still poses a notable risk if an attacker gains suitable access.
OpenCVE Enrichment