SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-33465

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kibana is vulnerable to a denial of service due to improper resource allocation, allowing authenticated users with low-level permissions to submit specially crafted requests that lead to excessive resource consumption. This can result in the application becoming unavailable, impacting service continuity. Organizations using Kibana should prioritize addressing this vulnerability to prevent potential disruptions in service availability.

CVE
CVE-2026-33465
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)