CVE-2026-49094

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kibana will consume excessive CPU and memory resources while processing the request. This results in Kibana becoming unavailable to all users until the service is manually recovered.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

01 Jun 2026, 13:31

Type Values Removed Values Added
References () https://discuss.elastic.co/t/kibana-8-19-16-security-update-esa-2026-39/386561/1 - () https://discuss.elastic.co/t/kibana-8-19-16-security-update-esa-2026-39/386561/1 - Vendor Advisory
First Time Elastic
Elastic kibana
CPE cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

28 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 21:16

Updated : 2026-06-01 13:31


NVD link : CVE-2026-49094

Mitre link : CVE-2026-49094

CVE.ORG link : CVE-2026-49094


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-400

Uncontrolled Resource Consumption