« Volver al listado

CVE-2026-26934

Estado: AnalizadaMedia (6.5)—

Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-only privileges to cause a Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted, malformed payload causing excessive resource consumption and resulting in Kibana becoming unresponsive or crashing.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-26934",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-26934",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-26T17:51:34.375595Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@elastic.co",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@elastic.co",
      "affectedData": [
        {
          "vendor": "Elastic",
          "product": "Kibana",
          "versions": [
            {
              "status": "affected",
              "version": "8.18.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.19.11"
            },
            {
              "status": "affected",
              "version": "9.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.2.5"
            },
            {
              "status": "affected",
              "version": "9.3.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.3.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-02-26T18:23:07.647",
  "references": [
    {
      "url": "https://discuss.elastic.co/t/kibana-8-19-12-9-2-6-9-3-1-security-update-esa-2026-12/385248",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@elastic.co"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@elastic.co",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-only privileges to cause a Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted, malformed payload causing excessive resource consumption and resulting in Kibana becoming unresponsive or crashing."
    },
    {
      "lang": "es",
      "value": "La Validación Incorrecta de la Cantidad Especificada en la Entrada (CWE-1284) en Kibana puede permitir a un atacante autenticado con privilegios de solo lectura causar una denegación de servicio mediante Manipulación de Datos de Entrada (CAPEC-153). Un atacante puede enviar una carga útil malformada y especialmente diseñada, causando un consumo excesivo de recursos y provocando que Kibana deje de responder o se bloquee."
    }
  ],
  "lastModified": "2026-06-17T10:26:24.820",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D88B8A69-2A25-4EB1-AAE4-C18A9F954D03",
              "versionEndExcluding": "8.19.12",
              "versionStartIncluding": "8.18.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F14ACA8C-46A2-42EF-9F63-AEF657C6736A",
              "versionEndExcluding": "9.2.6",
              "versionStartIncluding": "9.0.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:kibana:9.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E90DE12-A5EC-4C3C-A86E-BF5AA0778628"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@elastic.co"
}