What is CVE-2026-63261?
CVE-2026-63261 is an uncontrolled resource consumption (CWE-400) vulnerability in Kibana's machine learning feature that can lead to denial of service via excessive allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to exhaust server memory and cause unavailability.
Azərbaycanca: Kibana-nın maşın öyrənmə (machine learning) funksiyasında aşkar edilən CVE-2026-63261 zəifliyi, aşağı səlahiyyətli autentifikasiya olunmuş istifadəçiyə xüsusi hazırlanmış sorğu göndərərək serverin yaddaşını tükətməyə və xidmətə əlçatmazlığa (denial of service) səbəb olmağa imkan verir. Bu, nəzarətsiz resurs istehlakı (CWE-400) problemidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Does exploiting CVE-2026-63261 require authentication in Kibana?
Yes, exploiting this vulnerability requires the attacker to be a low-privileged authenticated user.
What is the potential impact of CVE-2026-63261?
This vulnerability can lead to exhaustion of server memory and cause denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.