PT-2026-31345 · Elastic · Kibana

Ismisepaul

+1

·

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-33459

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values. When multiple such requests are sent concurrently, the backend services become unstable, resulting in service disruption and deployment unavailability for all users. This issue is due to excessive allocation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-33459
BIT-KIBANA-2026-33459
CVE-2026-33459

Affected Products

Kibana