CVE-2026-26936: Inefficient Regular Expression Complexity in Kibana Leading to Denial of Service
Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26936?
CVE-2026-26936 is rated as a critical severity vulnerability due to its potential to cause Denial of Service.
How do I fix CVE-2026-26936?
To fix CVE-2026-26936, update your Elastic Kibana installation to the latest version that addresses this vulnerability.
What is the risk of CVE-2026-26936?
The risk associated with CVE-2026-26936 includes system crashes and degraded performance due to Denial of Service attacks.
Which versions of Kibana are affected by CVE-2026-26936?
CVE-2026-26936 affects multiple versions of Elastic Kibana, making it essential to identify your specific version for mitigation.
How does CVE-2026-26936 enable Denial of Service?
CVE-2026-26936 allows Denial of Service through inefficient regular expression processing, leading to exponential resource consumption.