Sploitus

CVE-2026-26934

No indexed exploits for CVE-2026-26934 yet

Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-only privileges to cause a Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted, malformed payload causing excessive resource consumption and resulting in Kibana becoming unresponsive or crashing.

Affected products
Kibana
Elastic Kibana
< 8.19.12, 9.2.6, 9.3.0
CVSS 3.1
6.5 MEDIUM
EPSS
0.3% (20th percentile)
Weakness
CWE-1284
NVD status
Analyzed
Published
2026-02-26
Attack patterns
CAPEC-153
CVE-2026-26934 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-26934 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-26934 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.