PT-2026-2635 · Elastic · Kibana

Bryan Garcia

+1

·

Published

2026-01-13

·

Updated

2026-01-16

·

CVE-2026-0543

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description A flaw exists in Kibana's Email Connector due to improper input validation. An attacker with authenticated access and sufficient view-level privileges can trigger an excessive allocation of resources by providing a specially crafted email address as a parameter. This can lead to complete service unavailability for all users, requiring a manual restart to restore functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

RCE

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-0543
BIT-KIBANA-2026-0543
CVE-2026-0543

Affected Products

Kibana