Denial of Service Vulnerability in Kibana by Elastic
CVE-2026-49096
4.3MEDIUM
What is CVE-2026-49096?
A vulnerability in Kibana allows authenticated users to exploit input data manipulation by creating malformed comments in case entries. When these comments are formatted for display, unhandled exceptions can occur, leading to denial of service. As a result, the affected case becomes inaccessible to all users until the problematic comment is removed. This vulnerability underscores the importance of input sanitization to maintain accessibility and stability in case management.
Affected Version(s)
Kibana 8.0.0 <= 8.19.19
Kibana 9.0.0 <= 9.3.4
Kibana 9.4.0