Impact
A missing authorization check in Kibana allows an authenticated user with minimal Elasticsearch privileges to bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default space. The vulnerability is characterized as Missing Authorization (CWE‑862) and is exploited by leveraging incorrectly configured access control settings (CAPEC‑180).
Affected Systems
Elastic Kibana is affected; the known impacted versions include the 9.4.6 and 9.5.1 releases mentioned in the Elastic advisory. No specific patch or version was listed in the vendor data, but the vulnerability applies to any deployment of Kibana that retains the default space configuration without additional hardening.
Risk and Exploitability
The CVSS base score of 4.3 classifies the flaw as medium severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly disclosed exploit at this time. However, the attack requires only an authenticated session with minimal Elasticsearch rights, a condition that could be met by many users. Based on the description, it is inferred that an attacker could exploit the flaw by sending crafted requests to Kibana endpoints that return Fleet metadata, thereby bypassing intended space and feature restrictions (inferred). The potential impact is the exposure of sensitive deployment details, which could facilitate further reconnaissance or credential theft.
OpenCVE Enrichment