Denial of Service Vulnerability in Timelion Visualization Plugin for Kibana by Elastic
CVE-2026-26940
6.5MEDIUM
What is CVE-2026-26940?
The Timelion visualization plugin in Kibana is affected by an improper validation issue that allows authenticated users to send crafted Timelion expressions. These expressions can overwrite internal series data properties with excessively large quantity values, potentially leading to Denial of Service through excessive allocation of resources.
Affected Version(s)
Kibana 9.3.0 <= 9.3.1
Kibana 9.0.0 <= 9.2.6
Kibana 8.0.0 <= 8.19.12