Denial of Service Vulnerability in Kibana by Elastic
CVE-2026-63261
6.5MEDIUM
What is CVE-2026-63261?
A vulnerability in Kibana allows low-privileged authenticated users to cause Uncontrolled Resource Consumption. By sending specially crafted requests to the machine learning features of Kibana, these users can lead to excessive memory allocation, which may exhaust server resources and result in a denial of service for all users. This situation underscores the importance of monitoring user permissions and implementing rate limiting to prevent such attacks.
Affected Version(s)
Kibana 8.0.0 <= 8.19.18
Kibana 9.4.0 <= 9.4.3
Kibana 9.0.0 <= 9.3.7