Vulnerability Description
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values. When multiple such requests are sent concurrently, the backend services become unstable, resulting in service disruption and deployment unavailability for all users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 8.15.0, < 8.19.14 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-33459?
CVE-2026-33459 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit s...
How severe is CVE-2026-33459?
CVE-2026-33459 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33459?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Kibana.