CVE-2026-42397

Summary

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value that causes excessive resource consumption, which may render Kibana unavailable.

Affected Software

VendorProductVersion RangeStatus
ElasticKibana9.4.0 <= 9.4.3affected
ElasticKibana9.3.0 <= 9.3.6affected

Weaknesses

  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling

References