Uncontrolled Resource Consumption in Kibana by Elastic
CVE-2026-49094
6.5MEDIUM
What is CVE-2026-49094?
A vulnerability in Kibana allows authenticated users with viewer-level access to exploit uncontrolled resource consumption by sending oversized input values to specific endpoints. This can lead to excessive CPU and memory usage, rendering the service unavailable until manual recovery is performed. Organizations using Kibana should be aware of this risk to maintain service availability.
Affected Version(s)
Kibana 8.0.0 <= 8.19.15