Description
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
Published: 2026-09-26
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

Uncontrolled resource consumption (CWE-400) in Kibana allows an attacker to cause excessive allocation of system resources, resulting in denial of service. The attack compromises the availability of the Kibana service but does not directly affect confidentiality or integrity of data processed by the service.

Affected Systems

Elastic Kibana is the affected product. The CNA data does not specify a vulnerable version, so any current installation of Kibana is potentially affected until the vendor releases an update. All deployments of Kibana from Elastic should be considered at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. EPSS is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, implying no documented exploitation at this time. Based on the description, it is inferred that the attack vector is a specially crafted request delivered over the network to an exposed Kibana endpoint.

Generated by OpenCVE AI on September 26, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to the latest version that includes the Elastic security fix.
  • Configure Kibana’s memory and resource limits in kibana.yml to restrict excessive allocation per request.
  • Apply firewall or rate‑limiting rules to reduce the number of requests from untrusted sources that reach Kibana.

Generated by OpenCVE AI on September 26, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 26 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Sat, 26 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
Title Uncontrolled Resource Consumption in Kibana Leading to denial of service
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-26T22:59:48.716Z

Reserved: 2026-09-21T13:29:41.420Z

Link: CVE-2026-94400

cve-icon Vulnrichment

Updated: 2026-09-26T22:59:46.311Z

cve-icon NVD

Status : Received

Published: 2026-09-26T21:16:56.513

Modified: 2026-09-26T23:16:40.340

Link: CVE-2026-94400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T23:00:15Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption