CyberRota Analysis
AI-GeneratedKibana is vulnerable due to a missing authorization flaw that allows users with only detection rule authoring privileges to execute unauthorized endpoint response actions on managed hosts. This can lead to significant security risks, as users may trigger actions like host isolation or process operations without the necessary permissions. Organizations using Kibana for Elastic Security should prioritize addressing this vulnerability to prevent potential misuse of automated response capabilities.
Original NVD Description
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.