Sploitus

CVE-2026-63139

No indexed exploits for CVE-2026-63139 yet

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially crafted request, causing the Kibana server process to terminate and resulting in a denial of service for all users of the affected Kibana instance.

Affected products
Kibana
Elastic Kibana
< 8.19.19, 9.3.8, 9.4.4
CVSS 3.1
6.5 MEDIUM
EPSS
0.3% (19th percentile)
Weakness
CWE-400
NVD status
Analyzed
Published
2026-07-21
Attack patterns
CAPEC-130
CVE-2026-63139 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-63139 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-63139 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.