Impact
Elastic Kibana has an incorrect authorization flaw (CWE‑863) that allows an attacker to access data they should not see. The vulnerability is tied to incorrectly configured security levels, which may expose sensitive information through CAPEC‑180 patterns. Although the product code is not malicious, the flaw can leak logs, dashboards, or other data that could aid an adversary in mapping or further attacks.
Affected Systems
Elastic Kibana is affected. No specific version range is listed, so all installations using the Kibana component from Elastic may be susceptible until a patch is applied.
Risk and Exploitability
The CVSS v3 score of 6.5 indicates medium severity. EPSS is not available, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting it has not been widely exploited. The likely attack vector is through a misconfigured or partially authenticated user who can trigger the broken authorization logic, especially if role‑based access control is not properly enforced. Once accessed, an attacker can read otherwise protected data.
OpenCVE Enrichment