CVE-2026-0543 Details
Description
Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector actions. The application attempts to process specially crafted email format, resulting in complete service unavailability for all users until manual restart is performed.
A denial-of-service vulnerability has been identified in Elastic Kibana's Email Connector, present in all versions of the 7.x branch and in the 8.x and 9.x branches up to certain versions. The issue arises from improper input validation, allowing an authenticated attacker with view-level privileges to send a specially crafted email address parameter. This manipulation causes excessive resource allocation, leading to complete service disruption for all users, which can only be resolved by manually restarting the application.
Users can upgrade to Kibana versions 8.19.10, 9.1.10, or 9.2.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/kibana-8-19-10-9-1-10-9-2-4-security-update-esa-2026-08/384523 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 7.0.0, <= 7.17.29 >= 8.0.0, < 8.19.0 >= 9.0.0, < 9.1.10 >= 9.2.0, < 9.2.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 22, 2026 | Initial Analysis | [email protected] |
| Jan 13, 2026 | New CVE Received | [email protected] |