CVE-2026-42397: Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value that causes excessive resource consumption, which may render Kibana unavailable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42397?
CVE-2026-42397 has a medium severity rating of 6.5.
How do I fix CVE-2026-42397?
To fix CVE-2026-42397, apply security updates provided by Elastic for affected versions of Kibana.
What impact does CVE-2026-42397 have on Kibana?
CVE-2026-42397 can lead to a denial of service by allowing excessive resource allocation through oversized input values.
Who can exploit CVE-2026-42397?
CVE-2026-42397 can be exploited by authenticated users submitting crafted requests to Entity Analytics endpoints.
Is there a risk of data exposure with CVE-2026-42397?
CVE-2026-42397 does not involve any confidentiality or integrity risks, but it could lead to availability issues.