Impact
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can allow a NoSQL injection attack (CAPEC-676). An authenticated user that can access the vulnerable query fields may submit specially crafted input that changes the intended query logic. This manipulation can return data that the user should not have permission to view, leading to an information disclosure incident.
Affected Systems
Elastic Kibana is the only vendor/product listed as affected. Specific version ranges are not detailed in the advisory; users should verify against Elastic’s security update catalog.
Risk and Exploitability
The CVSS score for this vulnerability is 6.5, indicating moderate severity. The exploit probability is not publicly available, and the entry is not listed in CISA’s KEV catalog. The attack requires an authenticated user with access to the affected query functionality, so the impact is limited to users who have legitimate permissions. In the absence of widespread exploitation evidence, the overall risk is moderate but still warrants timely review and mitigation.
OpenCVE Enrichment