CVE-2026-63261
Kibana vulnerability analysis and mitigation

Overview

CVE-2026-63261 is an Uncontrolled Resource Consumption (CWE-400) vulnerability in Elastic Kibana that can lead to denial of service via excessive memory allocation. A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users. Affected versions include Kibana 8.0.0 through 8.19.18, 9.0.0 through 9.3.7, and 9.4.0 through 9.4.3. The vulnerability was published on July 21, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption), where Kibana fails to properly limit or validate resource allocation triggered by requests to its machine learning feature endpoints. The attack vector is network-based, requires low privileges (an authenticated account), no user interaction, and low attack complexity, making it straightforward to trigger. The exploitation pattern aligns with CAPEC-130 (Excessive Allocation) and related patterns such as CAPEC-492 (Regular Expression Exponential Blowup) and CAPEC-147 (XML Ping of the Death), suggesting the crafted request may cause unbounded memory allocation within the ML processing pipeline (GitHub Advisory, Elastic Advisory).

Impact

Successful exploitation results in complete availability loss for the Kibana server — the service becomes unresponsive to all users once memory is exhausted. There is no confidentiality or integrity impact; the vulnerability is purely a denial-of-service condition. Because Kibana serves as the primary interface for Elasticsearch data visualization and operational dashboards, an outage can disrupt security monitoring, log analysis, and business intelligence workflows for all users of the affected instance (GitHub Advisory, Elastic Advisory).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, indicating that exploitation requires deliberate, authenticated interaction rather than opportunistic scanning. The EPSS score is approximately 0.24–0.27%, placing it in the 19th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Obtain low-privileged credentials: Acquire any valid Kibana user account with access to machine learning features — no administrative privileges are required.
  2. Identify target: Locate a Kibana instance running a vulnerable version (8.0.0–8.19.18, 9.0.0–9.3.7, or 9.4.0–9.4.3) accessible over the network.
  3. Craft malicious request: Construct a specially crafted HTTP request targeting a Kibana machine learning API endpoint designed to trigger excessive memory allocation (e.g., a request with parameters that cause unbounded resource consumption in the ML processing pipeline).
  4. Send the request: Authenticate to Kibana and submit the crafted request. The server begins allocating memory without adequate bounds checking.
  5. Trigger denial of service: Repeat or sustain the request as needed until the Kibana server exhausts available memory, causing it to become unresponsive to all users (GitHub Advisory, Elastic Advisory).

Indicators of compromise

  • Network: Repeated or sustained HTTP requests to Kibana machine learning API endpoints (e.g., paths under /api/ml/) from a single authenticated user or IP address, particularly with unusual payload sizes or structures.
  • Logs: Kibana server logs showing out-of-memory errors, heap exhaustion warnings, or Node.js process crashes; access logs with high-frequency requests to ML endpoints from a single session.
  • Process/System: Rapid increase in Kibana process memory consumption visible via system monitoring tools (e.g., top, htop, or APM agents); Kibana process termination or restart events triggered by the OS OOM killer.
  • Application: Kibana becoming unresponsive or returning 503/504 errors to all users following a period of elevated ML endpoint activity.

Mitigation and workarounds

Elastic has released patched versions: 8.19.19, 9.3.8, and 9.4.4 — upgrading to one of these versions is the recommended remediation (Elastic Advisory). As interim workarounds, administrators should restrict access to Kibana machine learning features to trusted users only using Kibana's role-based access control, implement rate limiting or request validation on ML endpoints at the network or reverse proxy layer, and monitor Kibana server memory consumption for anomalies. Organizations unable to upgrade immediately should consider disabling ML features entirely if they are not required.

Community reactions

Elastic published a security advisory (ESA-2026-72) covering this and related vulnerabilities in the Kibana 8.19.19, 9.3.8, and 9.4.4 release notes (Elastic Advisory). Tenable released detection plugins for the vulnerability, and third-party security monitoring platforms such as NetEye and INCIBE published advisories referencing the issue. Community reaction has been measured given the Medium severity rating and lack of known exploitation.

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72677HIGH7.3
  • Kibana logoKibana
  • kibana-9.3
NoYesAug 13, 2026
CVE-2026-72675HIGH7.1
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72681MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.4
NoYesAug 13, 2026
CVE-2026-72680MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72674MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.3
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management