Resource exhaustion in Kibana - CVE-2026-63261
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Kibana machine learning feature when handling a specially crafted request. A remote user can send a specially crafted request to cause a denial of service.
Only deployments with the machine learning feature enabled and accessible to authenticated users with low-privileged roles are vulnerable.