Description
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially crafted request, causing the Kibana server process to terminate and resulting in a denial of service for all users of the affected Kibana instance.
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication‑required, low‑privilege attacker can exploit Kibana’s Canvas feature to send a specially crafted request that causes uncontrolled allocation of resources. This excessive allocation triggers the Kibana server process to terminate, resulting in a denial of service for all users of the instance. The weakness is identified as CWE‑400 and corresponds to CAPEC‑130.

Affected Systems

The vendor Elastic’s Kibana product is affected. The data does not specify a particular release, so any Kibana installation without a subsequent update could be vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating moderate severity. The EPSS score is below 1%, suggesting an uncommon probability of exploitation in the wild, and it is not listed in CISA’s KEV catalog. Because the attack requires authenticated access, the risk is lower than an unauthenticated vulnerability but remains non‑negligible for environments where low‑privileged users have Canvas access.

Generated by OpenCVE AI on July 30, 2026 at 16:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to the latest patched release that resolves the Canvas allocation flaw.
  • If an upgrade is not immediately possible, restrict Canvas access to users with higher privileges or disable the feature entirely for low‑privileged accounts.
  • Apply traffic throttling or rate‑limiting on the Kibana endpoint to reduce the impact of crafted requests, thereby mitigating potential denial of service attacks.

Generated by OpenCVE AI on July 30, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially crafted request, causing the Kibana server process to terminate and resulting in a denial of service for all users of the affected Kibana instance.
Title Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-22T19:40:41.549Z

Reserved: 2026-07-15T18:23:57.166Z

Link: CVE-2026-63139

cve-icon Vulnrichment

Updated: 2026-07-22T19:31:56.667Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:30:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption