CVE-2026-26935: Improper Input Validation in Kibana Leading to Denial of Service
Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26935?
CVE-2026-26935 has been classified with a severity score that can lead to Denial of Service vulnerabilities in the Kibana application.
How do I fix CVE-2026-26935?
To address CVE-2026-26935, ensure that you update your Elastic Kibana to the latest version where this vulnerability is patched.
What can exploit CVE-2026-26935?
CVE-2026-26935 can be exploited through improper input validation in the internal Content Connectors search endpoint.
What is the impact of CVE-2026-26935?
The impact of CVE-2026-26935 can result in a Denial of Service, disrupting the normal operation of the Kibana service.
Which versions of Kibana are affected by CVE-2026-26935?
CVE-2026-26935 affects specific versions of Elastic Kibana prior to the security update that addresses the vulnerability.