Resource exhaustion in Kibana - CVE-2026-33464
Published: May 29, 2026
Kibana
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in an internal Kibana API when handling a specially crafted oversized payload. A remote user can submit a specially crafted oversized payload to cause a denial of service.
Exploitation requires authenticated access with the Viewer role or higher.