CVE-2026-49087 Details
Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk deletion request that causes excessive resource consumption, which may render Kibana unavailable.
A denial-of-service vulnerability has been identified in Elastic Kibana versions 8.0.0 prior to 8.19.14 and 9.0.0 prior to 9.3.3. This issue arises from the allocation of resources without limits or throttling, allowing an authenticated user to send a specially crafted bulk deletion request. This request causes excessive resource consumption, potentially rendering Kibana unavailable. The vulnerability affects deployments that use the Timeline feature, requiring an authenticated account with access to Timeline.
Users can upgrade to Kibana versions 8.19.15 or 9.3.4 to address this vulnerability. For those unable to upgrade, no workarounds are available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/kibana-8-19-15-9-3-4-security-update-esa-2026-49 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 8.0.0, < 8.19.15 >= 9.0.0, < 9.3.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |