CyberRota Analysis
AI-GeneratedKibana contains an incorrect authorization vulnerability that allows authenticated users with only read access to modify data by bypassing access control lists. This could result in unauthorized changes to the state of Entity Store maintainer tasks, potentially disabling critical maintenance functions for Entity Analytics. Organizations using Kibana, especially those implementing security solutions, should prioritize addressing this issue to prevent data integrity risks.
Original NVD Description
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.
Related CVEs
Other vulnerabilities affecting the same vendor(s)