CVE-2026-63261: Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published Jul 21, 2026
·Updated
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users.
Affected Software
1 affected component
Elastic Kibana
Event History
Jul 21, 2026
CVE Published
via MITRE·10:58 PM
Data Sourced
via MITRE·10:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63261?
CVE-2026-63261 has a severity rating of medium with a score of 6.5.
2
What are the potential impacts of CVE-2026-63261?
CVE-2026-63261 can lead to denial of service by exhausting available memory.
3
Who can exploit CVE-2026-63261?
A low-privileged authenticated user can exploit CVE-2026-63261 by sending specially crafted requests.
4
How can I mitigate CVE-2026-63261?
To mitigate CVE-2026-63261, restrict access to Kibana or implement resource limits.
5
Which software is affected by CVE-2026-63261?
CVE-2026-63261 affects Elastic Kibana.