CVE-2026-94400: Uncontrolled Resource Consumption in Kibana Leading to denial of service
Published Sep 26, 2026
·Updated
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
Affected Software
1 affected component
Elastic Kibana
Event History
Sep 26, 2026
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker needs low-level privileges and network access to the Kibana instance. No user interaction is required.
2
What is the expected security impact?
The reported impact is limited to availability: successful exploitation can cause denial of service. The supplied vector indicates no confidentiality or integrity impact.
3
Is this likely to be exploitable remotely?
Yes. The attack vector is network-based, so an attacker who can reach the affected Kibana service and has the required low privileges may be able to exploit it.