Impact
Elastic Kibana allows an authenticated user with read‑only access to the alerting feature to submit a specially crafted payload that causes the Kibana process to allocate resources without limits or throttling. The resulting resource exhaustion can prevent Kibana from serving requests for any user until the process is restarted, effectively denying service to all stakeholders. This vulnerability is classified as CWE-770, highlighting an unbounded resource allocation weakness.
Affected Systems
Elastic Kibana versions 8.19.20 and 9.4.5 are vulnerable. Only users who can access the alerting feature with read‑only privileges can trigger the attack, but any user affected by the resulting denial of service will experience the impact.
Risk and Exploitability
The vulnerability receives a CVSS score of 6.5, indicating a moderate severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet reported. However, the attack vector requires authentication; thus, internal attackers or compromised user accounts pose a realistic threat. A single malicious request is sufficient to consume excessive resources and leave the Kibana instance unavailable until a restart occurs.
OpenCVE Enrichment