Impact
An unhandled exception (CWE‑248) in Kibana allows an authenticated user with low‑privileged access to the Observability AI Assistant to submit specially crafted input that triggers an invalid operation and causes the Kibana process to terminate. This results in a denial of service for all users and spaces on the affected instance until the process is restarted.
Affected Systems
The vulnerability affects Elastic Kibana. Specific product versions are not disclosed in the CVE data.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the Epsilons score is unavailable while the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated access with the minimal feature rights to use the Observability AI Assistant; no additional pre‑conditions are disclosed. Once exploited, the entire Kibana service is halted, causing a service outage until administrators reboot the process or the system is restarted.
OpenCVE Enrichment