CVE-2026-63261
Analyzed Analyzed - Analysis Complete

Uncontrolled Resource Consumption in Kibana

Vulnerability report for CVE-2026-63261, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-08-03

Assigner: Elastic

Description

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-08-03
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
elastic kibana From 8.0.0 (inc) to 8.19.19 (exc)
elastic kibana From 9.0.0 (inc) to 9.3.8 (exc)
elastic kibana From 9.4.0 (inc) to 9.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled resource consumption issue in Kibana, classified under CWE-400. It allows a low-privileged authenticated user to send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory. This leads to a denial of service, making the server unavailable to all users.

Detection Guidance

Monitor memory usage on the Kibana server during normal operations and compare it to usage after users interact with machine learning features. Look for unusually high memory consumption or processes crashing due to out-of-memory errors.

Impact Analysis

If exploited, this vulnerability can cause your Kibana server to become unresponsive or crash due to excessive memory consumption. This disrupts access for all users, potentially leading to downtime and loss of service for critical operations relying on Kibana.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing service unavailability due to denial of service. GDPR requires data availability and security measures, while HIPAA mandates access to protected health information. A denial of service could disrupt these requirements.

Mitigation Strategies

Restrict access to Kibana machine learning features for low-privileged users. Update Kibana to the latest patched version if available. Monitor server memory usage and set up alerts for abnormal spikes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63261. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart