Haystack

Please anyone nudge for process after security user. Can not find any way to escalate to K user then to root. Spent the whole night only to bypass user. Found the cve but how to relate kibana hosted at localhost when all conf files are read only? Thanks in advance