Junglewise Threat Intelligence

CVE-2026-63260: Elastic Kibana denial of service via excessive memory allocation

CVE-2026-63260 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and management dashboard for the Elastic Stack. A security vulnerability allows a logged-in user with low-level permissions to crash the service by sending a specially crafted, oversized request. This results in a denial of service, making the dashboard unavailable to all other users and disrupting monitoring or data analysis operations.

Technical details

A vulnerability classified as Uncontrolled Resource Consumption (CWE-400) exists in Kibana due to improper handling of large request payloads. An authenticated attacker with low privileges can transmit a specially crafted, oversized request that triggers excessive memory allocation (CAPEC-130). This process exhausts the available heap memory in the Kibana process, leading to a crash and subsequent denial of service. The vulnerability is reachable over the network and does not require user interaction beyond authentication. The issue is resolved in Kibana versions 8.19.19, 9.3.8, and 9.4.4.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.18, 9.0.0 to 9.3.7, 9.4.0 to 9.4.3

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats