Resource exhaustion in Kibana - CVE-2026-49094
Published: May 29, 2026
Kibana
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the analytics collections management endpoint when processing a request containing an oversized input value. A remote user can submit a crafted request with an oversized input value to cause a denial of service.
This issue affects deployments where the behavioral analytics collections feature is available and does not affect Elastic Cloud Serverless.