CVE-2026-42397
Received Received - Intake

Allocation of Resources Without Limits in Kibana

Vulnerability report for CVE-2026-42397, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Elastic

Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value that causes excessive resource consumption, which may render Kibana unavailable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
elastic kibana *
elastic kibana From 9.3.0 (inc) to 9.3.7 (exc)
elastic kibana From 9.4.0 (inc) to 9.4.4 (exc)
elastic kibana 9.3.7
elastic kibana 9.4.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-42397 is an Allocation of Resources Without Limits or Throttling vulnerability in Kibana. It allows an authenticated user to submit a specially crafted request to Entity Analytics endpoints with an oversized input value. This causes excessive resource consumption, leading to a denial of service where Kibana may become unavailable.

Detection Guidance

To detect this vulnerability, monitor Kibana logs for excessive resource consumption or failed requests to Entity Analytics endpoints. Check for unusually high CPU or memory usage during requests. Use commands like 'curl -u username:password http://kibana-server:5601/api/entity_analytics/status' to test endpoint responses.

Impact Analysis

This vulnerability can impact you by making Kibana unavailable due to excessive resource consumption. If exploited, it may disrupt access to Kibana services, affecting operations that rely on the platform. The impact is limited to authenticated users who can submit crafted requests.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR or HIPAA by causing system unavailability, which may lead to disruptions in data processing or access to sensitive information. Denial of service conditions could violate availability requirements under these regulations.

Mitigation Strategies

Upgrade Kibana to versions 9.3.7 or 9.4.4 or later immediately. If upgrading is not possible, restrict access to Entity Analytics endpoints via network policies or firewall rules. Monitor system resources closely for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42397. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart