CVE-2026-63261: Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)
mediumvulnerability
security
Summary
CVE-2026-63261 is a vulnerability in Kibana where a low-privileged authenticated user can send a specially crafted request to the machine learning feature, causing uncontrolled resource consumption (where a system uses up memory or processing power without limits) that exhausts available memory and makes the server unavailable to all users, known as a denial of service attack. This vulnerability has a CVSS 4.0 severity rating (a 0-10 scale measuring how serious a vulnerability is).
Vulnerability Details
CVSS Score
6.5(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
network
Attack Complexity
low
Privileges Required
low
User Interaction
none
Disclosure Date
July 21, 2026
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63261
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 95%