Intel

AIKIDO-2026-10278

kibana is vulnerable to Improper Validation of Specified Quantity in Input

Improper Validation of Specified Quantity in InputCVE-2026-26934 Published Mar 2, 2026

65

Medium Risk

This Affects:

JSkibana
8.18.0 - 8.19.11
Fixed in 8.19.12
9.0.0 - 9.2.5
Fixed in 9.2.6
9.3.0 - 9.3.0
Fixed in 9.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Denial of Service (DoS). An authenticated attacker with view-only privileges can send a specially crafted malformed payload that causes excessive resource consumption, making Kibana unresponsive or causing it to crash.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

kibana is vulnerable to Improper Validation of Specified Quantity in Input in versions 8.18.0 - 8.19.11, 9.0.0 - 9.2.5 and 9.3.0 - 9.3.0.

How to fix this

Upgrade the kibana library to the patch version.