Impact
The vulnerability is a missing authorization check (CWE‑862) in an internal Kibana APM integration function. Any authenticated Kibana user can request APM server credentials that should only be visible to users with APM or Fleet administrative privileges. This results in the disclosure of sensitive credentials that could be used to access the APM server and potentially other downstream systems.
Affected Systems
Elastic Kibana is affected. Version details are not specified in the data provided; only the vendor and product are identified.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The attack requires an authenticated Kibana user but does not require elevated privileges; thus, any user who can log in to Kibana can exploit the flaw to read restricted APM server credentials.
OpenCVE Enrichment