Uncontrolled Resource Consumption in Kibana by Elastic
CVE-2026-63139
6.5MEDIUM
What is CVE-2026-63139?
An uncontrolled resource consumption flaw in Kibana's Canvas functionality allows an authenticated low-privileged user to send a specially crafted request, which can exhaust server resources. This exploitation may cause the Kibana server process to crash, leading to a denial of service for all users relying on that Kibana instance.
Affected Version(s)
Kibana 8.0.0 <= 8.19.18
Kibana 9.4.0 <= 9.4.3
Kibana 9.3.0 <= 9.3.7