Unrated severityNVD Advisory· Published Mar 19, 2026· Updated Mar 19, 2026
Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service
CVE-2026-26940
Description
Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows an authenticated user to send a specially crafted Timelion expression that overwrites internal series data properties with an excessively large quantity value.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.