Impact
The vulnerability is an incorrect authorization flaw (CWE-863) that occurs when Kibana’s access control is improperly configured. Because the system does not correctly enforce user permissions, an attacker can bypass restrictions and trigger a denial‑of‑service condition. The impact is that a single unauthorized request can render Kibana unavailable to legitimate users, compromising availability.
Affected Systems
Elastic Kibana is affected. The information does not list specific software versions, so any installation that uses Kibana may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates low to moderate severity. The EPSS score is not available, so the exact likelihood of exploitation is unclear, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote exploitation by abusing incorrectly configured access control levels; the attacker requires access to a Kibana instance that has weak or missing authentication.
OpenCVE Enrichment