---
cve: "CVE-2026-42399"
severity: "MEDIUM"
cvss: 6.5
epss: "33%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-05-28 21:16:30"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T12:20:56+02:00"
---

# CVE-2026-42399

> 6.5 MEDIUM

## Beschreibung

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visualization expression containing deeply chained function calls. The resulting data structure grows without bound, exhausting available memory and causing the Kibana service to crash and become unavailable to all users.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-400** — Uncontrolled Resource Consumption
  The product does not properly control the allocation and maintenance of a limited resource.

## Angriffsmuster (CAPEC)

- [CAPEC-147 — XML Ping of the Death](https://capec.mitre.org/data/definitions/147.html) _(Severity: Medium)_
- [CAPEC-227 — Sustained Client Engagement](https://capec.mitre.org/data/definitions/227.html)
- [CAPEC-492 — Regular Expression Exponential Blowup](https://capec.mitre.org/data/definitions/492.html)

## ATT&CK-Techniken

- [T1499 — Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499/)

## Patch verfügbar (OSV)

- 0ecfe314ed6ddebb736091bf37b3b6758209b73b (Commit)
- 7dcc32bebba091844c0207f9dae8fda6c7d08542 (Commit)

## Referenzen

- <https://discuss.elastic.co/t/kibana-8-19-16-and-9-3-5-security-update-esa-2026-36/386556>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-42399) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
