CVE-2026-26936 Details
Description
Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492).
A denial-of-service vulnerability has been identified in the AI Inference Anonymization Engine of Elastic Kibana. This issue arises from inefficient regular expression complexity, which can lead to exponential blowup in regex processing, causing a denial-of-service condition. The vulnerability affects Kibana versions 8.0.0 through 8.19.10 and 9.0.0 through 9.2.4. The problem occurs when the Elastic AI Assistant for Security is enabled with custom anonymization rules, allowing the vulnerable regex processing pipeline to execute.
Users can upgrade to Kibana versions 8.19.11 or 9.2.5 to address this vulnerability. For users unable to upgrade who have the AI Assistant enabled with custom anonymization rules, it is recommended to disable all custom anonymization rules in the Security AI settings.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/kibana-8-19-11-9-2-5-security-update-esa-2026-14/385250 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1333 | Inefficient Regular Expression Complexity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 8.0.0, < 8.19.11 >= 9.0.0, < 9.2.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 2, 2026 | Initial Analysis | [email protected] |
| Feb 26, 2026 | New CVE Received | [email protected] |