Impact
An authentication‑required, low‑privilege attacker can exploit Kibana’s Canvas feature to send a specially crafted request that causes uncontrolled allocation of resources. This excessive allocation triggers the Kibana server process to terminate, resulting in a denial of service for all users of the instance. The weakness is identified as CWE‑400 and corresponds to CAPEC‑130.
Affected Systems
The vendor Elastic’s Kibana product is affected. The data does not specify a particular release, so any Kibana installation without a subsequent update could be vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity. The EPSS score is below 1%, suggesting an uncommon probability of exploitation in the wild, and it is not listed in CISA’s KEV catalog. Because the attack requires authenticated access, the risk is lower than an unauthenticated vulnerability but remains non‑negligible for environments where low‑privileged users have Canvas access.
OpenCVE Enrichment