
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-63261 is an Uncontrolled Resource Consumption (CWE-400) vulnerability in Elastic Kibana that can lead to denial of service via excessive memory allocation. A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users. Affected versions include Kibana 8.0.0 through 8.19.18, 9.0.0 through 9.3.7, and 9.4.0 through 9.4.3. The vulnerability was published on July 21, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption), where Kibana fails to properly limit or validate resource allocation triggered by requests to its machine learning feature endpoints. The attack vector is network-based, requires low privileges (an authenticated account), no user interaction, and low attack complexity, making it straightforward to trigger. The exploitation pattern aligns with CAPEC-130 (Excessive Allocation) and related patterns such as CAPEC-492 (Regular Expression Exponential Blowup) and CAPEC-147 (XML Ping of the Death), suggesting the crafted request may cause unbounded memory allocation within the ML processing pipeline (GitHub Advisory, Elastic Advisory).
Successful exploitation results in complete availability loss for the Kibana server — the service becomes unresponsive to all users once memory is exhausted. There is no confidentiality or integrity impact; the vulnerability is purely a denial-of-service condition. Because Kibana serves as the primary interface for Elasticsearch data visualization and operational dashboards, an outage can disrupt security monitoring, log analysis, and business intelligence workflows for all users of the affected instance (GitHub Advisory, Elastic Advisory).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, indicating that exploitation requires deliberate, authenticated interaction rather than opportunistic scanning. The EPSS score is approximately 0.24–0.27%, placing it in the 19th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/api/ml/) from a single authenticated user or IP address, particularly with unusual payload sizes or structures.top, htop, or APM agents); Kibana process termination or restart events triggered by the OS OOM killer.Elastic has released patched versions: 8.19.19, 9.3.8, and 9.4.4 — upgrading to one of these versions is the recommended remediation (Elastic Advisory). As interim workarounds, administrators should restrict access to Kibana machine learning features to trusted users only using Kibana's role-based access control, implement rate limiting or request validation on ML endpoints at the network or reverse proxy layer, and monitor Kibana server memory consumption for anomalies. Organizations unable to upgrade immediately should consider disabling ML features entirely if they are not required.
Elastic published a security advisory (ESA-2026-72) covering this and related vulnerabilities in the Kibana 8.19.19, 9.3.8, and 9.4.4 release notes (Elastic Advisory). Tenable released detection plugins for the vulnerability, and third-party security monitoring platforms such as NetEye and INCIBE published advisories referencing the issue. Community reaction has been measured given the Medium severity rating and lack of known exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."