What is CVE-2026-63139?
An uncontrolled resource consumption vulnerability (CWE-400) was identified in Kibana's Canvas functionality, exploitable by an authenticated low-privileged user via a specially crafted request. This can lead to a denial of service (DoS) through excessive allocation. Kibana users are advised to update their software to the latest version.
Azərbaycanca: Kibana-nın Canvas funksionallığında autentifikasiya olunmuş aşağı səlahiyyətli istifadəçi tərəfindən xüsusi hazırlanmış sorğu vasitəsilə nəzarətsiz resurs istehlakı (CWE-400) zəifliyi aşkarlanıb. Bu, həddindən artıq yaddaş və ya CPU istifadəsi nəticəsində xidmət inkarına (DoS) səbəb ola bilər. Kibana istifadəçilərinə proqram təminatını ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which functionality of Kibana is affected by this vulnerability?
This vulnerability was identified in Kibana's Canvas functionality.
What level of access does an attacker need to exploit this vulnerability?
The attacker must be an authenticated low-privileged user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.