PatchSiren cyber security CVE debrief
CVE-2026-33464 Elastic CVE debrief
CVE-2026-33464 is a medium-severity uncontrolled resource consumption vulnerability in Kibana, published 2026-05-28. An authenticated low-privileged user can submit an oversized payload to an internal Kibana API, causing resource exhaustion and denial of service. The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) with attack pattern CAPEC-130 (Excessive Allocation). CVSS 3.1 score is 6.5 (MEDIUM), with vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H indicating network attack vector, low attack complexity, low privileges required, no user interaction, and high availability impact. Elastic has released security updates addressing this issue in Kibana versions 8.19.1, 6.9.3, 5.9.4, and 1.x as referenced in ESA-2026-32.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-29
Who should care
Organizations running Kibana instances with multi-user access, particularly those allowing low-privileged roles to interact with internal APIs. Security teams prioritizing availability of logging and analytics infrastructure. Elastic Stack administrators responsible for Kibana deployment and patch management.
Technical summary
The vulnerability exists in Kibana's handling of internal API requests where insufficient input validation allows oversized payloads to be processed. An attacker with valid low-privileged credentials can craft a request with excessive data allocation that consumes available system resources, rendering the Kibana process unresponsive. The attack requires network access to the Kibana instance and valid authentication, but no user interaction. Recovery requires service restart or automatic recovery after resource exhaustion. The CVSS availability impact is rated HIGH due to complete denial of service to all users.
Defensive priority
medium
Recommended defensive actions
- Apply security updates to Kibana versions 8.19.1, 6.9.3, 5.9.4, or later as specified in Elastic security advisory ESA-2026-32
- Implement input size limits and request validation on internal Kibana APIs
- Monitor for anomalous API requests with unusually large payloads from authenticated users
- Review and restrict low-privileged user access to internal Kibana APIs where possible
- Enable resource monitoring and alerting for Kibana process memory and CPU utilization
Evidence notes
Vulnerability details sourced from NVD modified feed with Elastic security advisory reference. Vendor attribution to Elastic based on reference domain candidate evidence with low confidence flag requiring review.
Official resources
-
CVE-2026-33464 CVE record
CVE.org
-
CVE-2026-33464 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-28