Denial of Service Vulnerability in Kibana by Elastic
CVE-2026-33459
6.5MEDIUM
What is CVE-2026-33459?
An uncontrolled resource consumption vulnerability in Kibana allows authenticated users with access to the automatic import feature to cause denial of service. By submitting specially crafted requests with large input values, multiple concurrent requests can overwhelm backend services, leading to instability and unavailability of the Kibana deployment for all users.
Affected Version(s)
Kibana 9.3.0 <= 9.3.2
Kibana 8.15.0 <= 8.19.13
Kibana 9.0.0 <= 9.2.7