Sploitus

CVE-2026-26940

No indexed exploits for CVE-2026-26940 yet

Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows an authenticated user to send a specially crafted Timelion expression that overwrites internal series data properties with an excessively large quantity value.

Affected products
Kibana
Elastic Kibana
< 8.19.13, 9.2.7, 9.3.2
CVSS 3.1
6.5 MEDIUM
EPSS
0.3% (19th percentile)
Weakness
CWE-1284
NVD status
Analyzed
Published
2026-03-19
Attack patterns
CAPEC-130
CVE-2026-26940 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-26940 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-26940 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.