Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33459

24
FAUCET Score

CVE-2026-33459 is an uncontrolled resource consumption vulnerability in Kibana's automatic import feature that allows authenticated users to trigger denial of service attacks by submitting specially crafted requests with excessively large input values, particularly when multiple requests are sent concurrently to destabilize backend services. The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector that requires low complexity and valid user credentials, but causes high availability impact resulting in service disruption across all users. The attack has not been observed in active exploitation according to KEV records, with an extremely low EPSS score of 0.000460 indicating minimal real-world exploitation probability compared to other vulnerabilities. No public exploit code is widely available, and community attention remains limited as evidenced by the inactive Hot List status. Organizations running Kibana should prioritize patching this vulnerability to prevent authenticated attackers from leveraging the automatic import feature to disrupt service availability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.15.0, < 8.19.14CPE matchmatch criteria
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.2.8CPE matchmatch criteria
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
>= 9.3.0, < 9.3.3CPE matchmatch criteria
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
>= 8.15.0, <= 8.19.13CPE match
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
>= 9.0.0, <= 9.2.7CPE match
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 17th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

discuss.elastic.co / t/kibana-8-19-14-9-2-8-9-3-3-security-update-esa-2026-26/385814
Vendor Advisory