Impact
An uncaught exception in Kibana, caused by improper input validation, is triggered when an authenticated user with low privileges submits specially crafted data. The exception propagates on an execution path and terminates the entire Kibana process. As a result, the service becomes unavailable to all users until a restart is performed, and the condition can be repeated. The impact is a complete denial of service to the Kibana instance, affecting confidentiality and availability of the application’s functionality.
Affected Systems
Elastic Kibana is the only vendor/product listed as affected; no specific version information is provided in the CNA data. The vulnerability applies to any Kibana installation where the affected code paths are active.
Risk and Exploitability
The CVSS score of 6.5 classifies the risk as medium, but the lack of a containment mechanism means the denial of service can be repeatedly triggered. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting a lower current exploitation probability but a non‑negligible threat if the patch is not applied. The likely attack vector requires an authenticated session with low‑privileged access, requiring the attacker to interact with Kibana’s API or UI to submit the malformed input.
OpenCVE Enrichment