Impact
Kibana is vulnerable to uncontrolled resource consumption, a flaw in which the application allocates memory or other resources without sufficient validation. A low‑privileged authenticated user can send a specially crafted request to the machine‑learning feature, causing the server to exhaust its available memory and become unavailable to all users. The impact is a denial of service for the entire Kibana instance, affecting availability but not confidentiality or integrity.
Affected Systems
Elastic Kibana is the affected product. No specific version information is provided in the CNA data, so the scope of affected releases is unclear. Reference information indicates that recent releases 8.19.x and 8.20.x are relevant, but older versions may also be impacted if they contain the same machine‑learning implementation.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is less than 1%, meaning exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated request sent by a low‑privileged user to the Kibana machine‑learning endpoint, which then consumes all available memory.
OpenCVE Enrichment