Denial of Service Issue in Kibana by Elastic
CVE-2026-26936
4.9MEDIUM
What is CVE-2026-26936?
The vulnerability arises from inefficient regular expression handling in the AI Inference Anonymization Engine of Kibana, which can trigger a Denial of Service (DoS) condition. This is caused by exponential blowup scenarios when processing complex regular expressions, allowing potential attackers to overwhelm the system and disrupt services.
Affected Version(s)
Kibana 9.0.0 <= 9.2.4
Kibana 8.0.0 <= 8.19.10