Denial of Service Vulnerability in Timelion Visualization Plugin for Kibana by Elastic
CVE-2026-26940
6.5MEDIUM
What is CVE-2026-26940?
The Timelion visualization plugin in Kibana is affected by an improper validation issue that allows authenticated users to send crafted Timelion expressions. These expressions can overwrite internal series data properties with excessively large quantity values, potentially leading to Denial of Service through excessive allocation of resources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kibana 9.3.0 <= 9.3.1
Kibana 9.0.0 <= 9.2.6
Kibana 8.0.0 <= 8.19.12