PT-2026-44491 · Elastic · Kibana

Ismisepaul

+1

·

Published

2026-05-28

·

Updated

2026-06-01

·

CVE-2026-33464

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description Uncontrolled Resource Consumption in Kibana can lead to a denial of service via Excessive Allocation. An authenticated user with a low-privileged role can submit a specially crafted, oversized payload to an internal Kibana API, causing the process to exhaust available resources and become unresponsive to all users until the service recovers or is restarted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-33464
BIT-KIBANA-2026-33464
CVE-2026-33464

Affected Products

Kibana