Impact
Kibana is vulnerable to excessive allocation of resources when an authenticated user submits a crafted request. This flaw, a classic instance of allocation without limits or throttling, can drain system memory or CPU, potentially rendering the application unavailable to legitimate users. The weakness is classified as CWE-770 and is noted to fall under the CAPEC-130 category of excessive allocation.
Affected Systems
The affected software is Elastic's Kibana product. No specific product versions are listed in the publicly available data, so the scope applies broadly to all Kibana installations until a patch is deployed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. Because the flaw requires authentication, threat actors must have valid account credentials, but no additional prerequisites are highlighted in the description. The EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet confirmed. Nonetheless, an attacker who can log in can trigger the denial of service by overloading system resources.
OpenCVE Enrichment