Denial of Service Vulnerability in Kibana by Elastic
CVE-2026-63261

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-63261?

A vulnerability in Kibana allows low-privileged authenticated users to cause Uncontrolled Resource Consumption. By sending specially crafted requests to the machine learning features of Kibana, these users can lead to excessive memory allocation, which may exhaust server resources and result in a denial of service for all users. This situation underscores the importance of monitoring user permissions and implementing rate limiting to prevent such attacks.

Affected Version(s)

Kibana 8.0.0 <= 8.19.18

Kibana 9.4.0 <= 9.4.3

Kibana 9.0.0 <= 9.3.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.