Impact
The vulnerability arises from an Incorrect Authorization flaw (CWE‑863) that exists in the machine learning feature of Kibana. A user who is authenticated to the Kibana instance can abuse the ML APIs to initiate jobs or queries that they should not have permission to execute, thereby consuming CPU, memory, or storage resources that belong to higher‑privilege scopes. The attack requires legitimate authentication, but the scope of privilege is wrongly granted, so an attacker can increase resource consumption beyond their allowed quota. The inferred attack vector is an authenticated user leveraging existing access control.
Affected Systems
Elastic Kibana is the affected product. No specific version range is listed in the advisory, so all installed instances might be vulnerable until a patch is applied. Administrators should verify the version and whether the machine learning capability is active.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not in the CISA KEV catalogue, suggesting it is currently not a known exploit target. Nonetheless, because it permits unauthorized resource usage by users who already have access, it can degrade cluster performance or exhaust quotas, and the risk is highest when the ML feature is enabled for a wide range of users.
OpenCVE Enrichment