Junglewise Threat Intelligence

CVE-2026-33464: Elastic Kibana denial of service via uncontrolled resource consumption

CVE-2026-33464 · Severity: medium · CVSS 6.5 · Published 2026-05-28

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a popular data visualization and management platform for the Elastic Stack, is vulnerable to a denial-of-service attack. An authenticated user with even low-level permissions can send a specially crafted request that causes the system to exhaust its resources. This results in the platform becoming unresponsive to all users, potentially disrupting business operations and data monitoring until the service is manually restarted or recovers.

Technical details

A vulnerability classified as Uncontrolled Resource Consumption (CWE-400) exists in Kibana's internal APIs. The flaw allows an authenticated attacker with low-privileged access (such as the Viewer role) to submit a specially crafted, oversized payload that triggers excessive memory or CPU allocation (CAPEC-130). This resource exhaustion causes the Kibana process to become unresponsive, effectively creating a Denial of Service (DoS) condition. The issue affects versions 8.x up to 8.19.15, 9.x up to 9.3.4, and version 9.4.0. It has been remediated in versions 8.19.16, 9.3.5, and 9.4.1.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.15, 9.0.0 to 9.3.4, 9.4.0

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory
  • 2026-05-28: patched: Remediated in versions 8.19.16, 9.3.5, and 9.4.1

References

Related threats