Impact
Incorrect Authorization (CWE‑863) in Kibana allows an attacker that can authenticate from more than one realm to misuse another user’s privileged data. The flaw is that the system does not properly enforce Access Control Lists when two logged‑in principals share a username. As a result, a user can read, alter, and delete another user’s Elastic AI Assistant Knowledge Base entries, which are intended to be private.
Affected Systems
Environment involves Elastic Kibana. No specific version numbers are supplied, so the vulnerability applies to any deployed instance where multiple authentication realms coexist and users with identical usernames are permitted.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation evidence is not yet documented. The likely attack vector requires the attacker to already be authenticated; however, the presence of multiple realms and username collision is a plausible configuration in many deployments, raising the practical risk for misconfigured environments.
OpenCVE Enrichment