CyberRota Analysis
AI-GeneratedThe Kibana Fleet feature is vulnerable to a path traversal issue that allows low-privileged users to manipulate actions taken by higher-privileged users, potentially leading to unauthorized deletion of critical resources, including accounts with elevated privileges. Organizations utilizing Kibana should prioritize addressing this vulnerability to prevent potential exploitation that could compromise their resource management and security posture. Immediate attention is recommended for those with administrative interfaces exposed to low-privileged user interactions.
Original NVD Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
Related CVEs
Other vulnerabilities affecting the same vendor(s)