Uncontrolled Resource Consumption in Kibana by Elastic
CVE-2026-49094

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-49094?

A vulnerability in Kibana allows authenticated users with viewer-level access to exploit uncontrolled resource consumption by sending oversized input values to specific endpoints. This can lead to excessive CPU and memory usage, rendering the service unavailable until manual recovery is performed. Organizations using Kibana should be aware of this risk to maintain service availability.

Affected Version(s)

Kibana 8.0.0 <= 8.19.15

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.