Uncontrolled Resource Consumption Vulnerability in Kibana by Elastic
CVE-2026-42400
6.5MEDIUM
What is CVE-2026-42400?
An uncontrolled resource consumption vulnerability has been identified in Kibana by Elastic, which could lead to denial of service. This arises from an authenticated user being able to send a specially crafted compressed request payload that bypasses initial authorization checks, thereby causing excessive memory and CPU usage. The result may render a Kibana instance unresponsive or ultimately lead to a crash, severely impacting system availability and performance.
Affected Version(s)
Kibana 9.4.0 <= 9.4.1
Kibana 9.0.0 <= 9.3.4
Kibana 8.0.0 <= 8.19.15