Sploitus

CVE-2026-63260

No indexed exploits for CVE-2026-63260 yet

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payload. Processing this user-supplied input requires resource-intensive memory allocation that can exhaust the available heap memory in the Kibana process, causing it to crash and become unavailable to all users.

Affected products
Kibana
Elastic Kibana
< 8.19.19, 9.3.8, 9.4.4
CVSS 3.1
6.5 MEDIUM
EPSS
0.3% (19th percentile)
Weakness
CWE-400
NVD status
Analyzed
Published
2026-07-21
Attack patterns
CAPEC-130
CVE-2026-63260 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-63260 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-63260 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.