CVE-2026-49089: Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana process to spend an unbounded amount of time evaluating it. An authenticated user with read-only privileges was able to send a single request that left Kibana unable to serve any user until the process was restarted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49089?
The severity of CVE-2026-49089 is considered medium with a CVSS score of 6.5.
How does CVE-2026-49089 lead to denial of service?
CVE-2026-49089 enables denial of service by allowing excessive resource allocation without limits or throttling in Kibana.
What systems are affected by CVE-2026-49089?
CVE-2026-49089 specifically affects Kibana software.
How do I fix CVE-2026-49089?
Fixing CVE-2026-49089 involves implementing limits on query expression sizes within Kibana.
When was CVE-2026-49089 published?
CVE-2026-49089 was published on August 13, 2026.