Impact
The vulnerability is an Incorrect Authorization flaw (CWE-863) in Kibana that permits an attacker to alter configuration settings without having proper privileges. By exploiting this weakness, an attacker can modify Kibana's operational parameters, potentially compromising the system's intended behavior. The description identifies the problem as misconfigured access control.
Affected Systems
Elastic Kibana is the affected product. The vendor is Elastic, and the product is Kibana. Specific affected version numbers are not listed in the supplied data, so all currently running versions of Kibana should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score is 8.1, which represents a high severity vulnerability. No EPSS score is available, making it unclear how frequently the vulnerability is targeted in the wild. The issue is not listed in the CISA KEV catalog, indicating that known exploitation has not been reported. Based on the description, the likely attack vector is internal or network access to the Kibana interface, where an attacker can use the incorrectly configured access control to modify settings. The weakness is categorized as CWE-863 and is associated with CAPEC-180 (Exploiting Incorrectly Configured Access Control Security Levels).
OpenCVE Enrichment