Impact
An authenticated user who is authorized to manage maintenance windows can submit a specially crafted, malformed payload that forces Kibana to consume excessive resources. The process becomes unresponsive for all users and does not recover until manual intervention is performed, effectively denying service to the entire Kibana instance.
Affected Systems
The vulnerability affects the Elastic Kibana product. The advisory does not list specific version numbers, so any Kibana installation that accepts maintenance window configurations is potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity attack. EPSS data is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting no widely known public exploitation. The attack requires legitimate credentials with maintenance window privileges, limiting the threat to insiders or compromised accounts, but once the permission boundary is crossed the system can be taken offline.
OpenCVE Enrichment