SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-63261

MEDIUM · CVSS 6.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Kibana is vulnerable to uncontrolled resource consumption, allowing low-privileged authenticated users to send crafted requests that can exhaust server memory and result in a denial of service. This vulnerability could impact the availability of Kibana for all users, making it critical for organizations utilizing Kibana to prioritize mitigation efforts. Users managing Kibana environments should assess their configurations and implement necessary safeguards to prevent exploitation.

CVE
CVE-2026-63261
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%

Original NVD Description

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users.

Related CVEs

Other vulnerabilities affecting the same vendor(s)