---
cve: "CVE-2026-49089"
severity: "MEDIUM"
cvss: 6.5
epss: "33%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-08-13 19:08:07"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T19:03:06+02:00"
---

# CVE-2026-49089

> 6.5 MEDIUM

## Beschreibung

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana process to spend an unbounded amount of time evaluating it. An authenticated user with read-only privileges was able to send a single request that left Kibana unable to serve any user until the process was restarted.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-770** — Allocation of Resources Without Limits or Throttling
  The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

## Angriffsmuster (CAPEC)

- [CAPEC-125 — Flooding](https://capec.mitre.org/data/definitions/125.html) _(Severity: Medium)_
- [CAPEC-130 — Excessive Allocation](https://capec.mitre.org/data/definitions/130.html) _(Severity: Medium)_
- [CAPEC-147 — XML Ping of the Death](https://capec.mitre.org/data/definitions/147.html) _(Severity: Medium)_
- [CAPEC-197 — Exponential Data Expansion](https://capec.mitre.org/data/definitions/197.html) _(Severity: Medium)_
- [CAPEC-229 — Serialized Data Parameter Blowup](https://capec.mitre.org/data/definitions/229.html) _(Severity: High)_
- [CAPEC-230 — Serialized Data with Nested Payloads](https://capec.mitre.org/data/definitions/230.html) _(Severity: High)_
- [CAPEC-231 — Oversized Serialized Data Payloads](https://capec.mitre.org/data/definitions/231.html) _(Severity: High)_
- [CAPEC-469 — HTTP DoS](https://capec.mitre.org/data/definitions/469.html) _(Severity: Low)_

## ATT&CK-Techniken

- [T1498.001 — Network Denial of Service: Direct Network Flood](https://attack.mitre.org/techniques/T1498/001/)
- [T1499 — Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499/)
- [T1499.003 — Endpoint Denial of Service:Application Exhaustion Flood](https://attack.mitre.org/techniques/T1499/003/)
- [T1499.002 — Endpoint Denial of Service: Service Exhaustion Flood](https://attack.mitre.org/techniques/T1499/002/)

## Patch verfügbar (OSV)

- 91f5381ece296ddc32b554f997269478b9224af8 (Commit)
- adc1f04ffdd393d1977990338d5512c5eaf1ce94 (Commit)

## Referenzen

- <https://discuss.elastic.co/t/kibana-8-19-20-9-4-5-security-update-esa-2026-137/389511>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-49089) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
