Impact
The vulnerability resides in Elastic Kibana’s handling of visualization payloads. An authenticated user with only low privileges can supply a specially crafted, malformed payload that is not properly validated. When the server processes this request it allocates memory without limits, leading to unbounded memory growth. As the memory usage reaches system capacity, the Kibana process is terminated by the host’s OOM killer and the service becomes unavailable to all users until it is restarted.
Affected Systems
Elastic Kibana is impacted. No specific version information is provided in the CNA data, so the vulnerability applies to all currently supported releases of Kibana unless a patch has already been applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Although EPSS data is not available, the attack requires authenticated low‑privileged access and the attacker can trigger service downtime by submitting the malformed visualization. The exploit path is straightforward: submit the crafted payload, cause memory exhaustion, and deny service to all users. The impact is disruptive but does not compromise data confidentiality or integrity.
OpenCVE Enrichment