
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33459 is an Uncontrolled Resource Consumption (CWE-400) vulnerability in Elastic Kibana that can lead to denial of service via excessive allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values; when sent concurrently, these requests destabilize backend services and render the deployment unavailable for all users. Affected versions include Kibana 8.15.0–8.19.13, 9.0.0–9.2.7, and 9.3.0–9.3.2. The vulnerability was published on April 8, 2026, with patches released for versions 8.19.14, 9.2.8, and 9.3.3. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption), where Kibana's automatic import feature fails to enforce adequate limits on input size or request rate. An authenticated attacker can craft HTTP requests containing excessively large input values and submit them concurrently to the automatic import endpoint, triggering excessive memory or CPU allocation on backend services. No input validation or resource throttling is applied to reject or limit oversized payloads, allowing the attacker to exhaust available resources. The attack pattern aligns with CAPEC-130 (Excessive Allocation) and has secondary relevance to CAPEC-492 (Regular Expression Exponential Blowup) and CAPEC-147 (XML Ping of the Death) (GitHub Advisory, Elastic Advisory).
Successful exploitation results in a denial of service affecting the availability of the entire Kibana deployment for all users, not just the attacker. Backend services become unstable under concurrent oversized requests, causing service disruption and deployment unavailability. There is no impact on data confidentiality or integrity — the vulnerability is purely an availability concern. Organizations relying on Kibana for security monitoring, log analysis, or operational dashboards could experience significant operational disruption during an attack (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of reporting. The EPSS score is approximately 0.039–0.053%, placing it in the 17th percentile for exploitation likelihood within 30 days. Exploitation requires authentication (low-privilege access) and the ability to reach the automatic import feature, which somewhat limits the attack surface. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Elastic Advisory).
curl, ab (Apache Bench), or a custom script to send multiple such oversized requests simultaneously, maximizing resource consumption on the backend.Elastic has released patched versions addressing this vulnerability: 8.19.14, 9.2.8, and 9.3.3. Organizations should upgrade to one of these versions as the primary remediation. As interim workarounds, administrators should implement rate limiting and request size validation on the automatic import feature, restrict access to the automatic import feature to trusted users only, and monitor backend resource consumption for unusual spikes. Input validation to reject requests with excessively large values should also be considered if immediate patching is not feasible (Elastic Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."