CVE-2026-33459 is an uncontrolled resource consumption vulnerability in Kibana's automatic import feature that allows authenticated users to trigger denial of service attacks by submitting specially crafted requests with excessively large input values, particularly when multiple requests are sent concurrently to destabilize backend services. The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector that requires low complexity and valid user credentials, but causes high availability impact resulting in service disruption across all users. The attack has not been observed in active exploitation according to KEV records, with an extremely low EPSS score of 0.000460 indicating minimal real-world exploitation probability compared to other vulnerabilities. No public exploit code is widely available, and community attention remains limited as evidenced by the inactive Hot List status. Organizations running Kibana should prioritize patching this vulnerability to prevent authenticated attackers from leveraging the automatic import feature to disrupt service availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.15.0, < 8.19.14CPE matchmatch criteria | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.2.8CPE matchmatch criteria | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | ||
>= 9.3.0, < 9.3.3CPE matchmatch criteria | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | ||
>= 8.15.0, <= 8.19.13CPE match | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.2.7CPE match | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.