CyberRota Analysis
AI-GeneratedKibana Entity Analytics is vulnerable due to incorrect authorization, allowing authenticated users with only read-level access to halt the Privilege Monitoring engine task for a specific Kibana space, despite lacking Elasticsearch privileges. This can lead to a significant loss of security monitoring capabilities, as the engine will falsely report a healthy state while failing to collect critical data. Organizations utilizing Kibana for security monitoring should prioritize addressing this vulnerability to maintain effective oversight and prevent potential security lapses.
Original NVD Description
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.
Related CVEs
Other vulnerabilities affecting the same vendor(s)