CVE-2026-26937: Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published Feb 26, 2026
·Updated
Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)
Affected Software
3 affected components
Elastic Kibana
Elastic Kibana>=8.0.0<8.19.11
Elastic Kibana>=9.0.0<9.2.5
Event History
Feb 26, 2026
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:32 PM
DescriptionSeverityWeaknessAffected Software
Jun 28, 58142
Event
via FIRST·02:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-26937?
CVE-2026-26937 is classified as a Denial of Service vulnerability due to uncontrolled resource consumption.
2
How do I fix CVE-2026-26937?
To mitigate CVE-2026-26937, update Kibana to the latest version beyond 9.2.5 or 8.19.11.
3
Which versions of Kibana are affected by CVE-2026-26937?
CVE-2026-26937 affects Kibana versions from 8.0.0 to 8.19.11 and 9.0.0 to 9.2.5.
4
What type of vulnerability is CVE-2026-26937?
CVE-2026-26937 is an uncontrolled resource consumption vulnerability, leading to potential Denial of Service.
5
What components of Kibana are impacted by CVE-2026-26937?
The vulnerability specifically impacts the Timelion component in Kibana.