High severity7.6NVD Advisory· Published Jun 10, 2025· Updated Jun 17, 2026
CVE-2024-43706
CVE-2024-43706
Description
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords2 versions
>= 8.12.0, < 8.12.1+ 1 more
- (no CPE)range: >= 8.12.0, < 8.12.1
- (no CPE)range: >= 8.12.0, < 8.12.1
Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-21/379064nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.