Resource Management Flaw in Kibana by Elastic
CVE-2026-42397
6.5MEDIUM
What is CVE-2026-42397?
A vulnerability within Kibana allows an authenticated user to exploit the resource allocation mechanism by submitting a specially crafted request to the Entity Analytics endpoints. This request contains an oversized input value, which can lead to excessive resource consumption. Ultimately, this results in a denial of service condition, making Kibana unavailable and disrupting user operations.
Affected Version(s)
Kibana 9.4.0 <= 9.4.3
Kibana 9.3.0 <= 9.3.6