CVE-2026-63261

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-21 23:18

Updated : 2026-08-03 16:38


NVD link : CVE-2026-63261

Mitre link : CVE-2026-63261

CVE.ORG link : CVE-2026-63261


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-400

Uncontrolled Resource Consumption