CyberRota Analysis
AI-GeneratedThe Kibana Fleet feature is vulnerable to a path traversal issue that allows low-privileged users with write access to potentially delete unintended internal resources. This vulnerability can be exploited if an administrator interacts with the affected Fleet interface, leading to unauthorized resource deletion. Organizations using Kibana should prioritize addressing this issue to mitigate the risk of accidental or malicious data loss.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.
Related CVEs
Other vulnerabilities affecting the same vendor(s)