CVE-2026-26940: Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service
Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows an authenticated user to send a specially crafted Timelion expression that overwrites internal series data properties with an excessively large quantity value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26940?
CVE-2026-26940 has been classified as a denial of service vulnerability due to improper input validation in the Kibana Timelion plugin.
How do I fix CVE-2026-26940?
To fix CVE-2026-26940, it is recommended to update to the latest version of the Kibana Timelion plugin where the vulnerability has been addressed.
What impact does CVE-2026-26940 have on my system?
CVE-2026-26940 can lead to denial of service, potentially causing excessive resource allocation and making the affected Kibana instance unresponsive.
Who is affected by CVE-2026-26940?
Any user utilizing the Timelion visualization plugin in Kibana is potentially affected by CVE-2026-26940.
Is user authentication required to exploit CVE-2026-26940?
Yes, exploitation of CVE-2026-26940 requires an authenticated user, as the vulnerability is located in an authenticated component of Kibana.