VYPR
Medium severity6.5NVD Advisory· Published May 28, 2026· Updated Jun 17, 2026

CVE-2026-33464

CVE-2026-33464

Description

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially crafted, oversized payload to an internal Kibana API, causing the Kibana process to exhaust available resources and become unresponsive to all users until the service recovers or is restarted.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Elastic/Kibanainferred4 versions
    (expand)+ 3 more
    • (no CPE)
    • cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*range: >=8.0.0,<8.19.16
    • cpe:2.3:a:elastic:kibana:9.4.0:*:*:*:*:*:*:*
    • (no CPE)
  • osv-coords2 versions
    < 9.3.5+ 1 more
    • (no CPE)range: < 9.3.5
    • (no CPE)range: < 9.3.5

Patches

Vulnerability mechanics

References

1

News mentions

1