Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-42397

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Jul 21, 2026
Vendor unknown

Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value that causes excessive resource consumption, which may render Kibana unavailable.

References