CVE-2024-43706: Kibana Improper Authorization
Published Jun 10, 2025
·Updated
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
Affected Software
2 affected components
Elastic Kibana
Elastic Kibana<=8.12.0
Event History
Jun 10, 2025
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43706?
CVE-2024-43706 is classified as a high-severity vulnerability due to its potential for privilege abuse.
2
How do I fix CVE-2024-43706?
To fix CVE-2024-43706, ensure you upgrade to the latest version of Elastic Kibana where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2024-43706?
CVE-2024-43706 is an improper authorization vulnerability found in Kibana.
4
What consequences does CVE-2024-43706 pose?
CVE-2024-43706 can lead to privilege abuse via unauthorized access to synthetic monitor endpoints.
5
Which software is affected by CVE-2024-43706?
CVE-2024-43706 affects Elastic Kibana, specifically versions prior to the security updates.