---
cve: "CVE-2026-94400"
severity: "MEDIUM"
cvss: 6.5
epss: "0.4%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-09-26 21:16:56"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-30T12:18:39+02:00"
---

# CVE-2026-94400

> 6.5 MEDIUM

## Beschreibung

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)

## CNA-Record (Kanon, cvelistV5)

- CNA: **elastic**
- State: PUBLISHED
- Stand: 2026-09-26 22:59:48
- CNA-CVSS: **6.5** (`CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-400** — Uncontrolled Resource Consumption
  The product does not properly control the allocation and maintenance of a limited resource.

## Angriffsmuster (CAPEC)

- [CAPEC-147 — XML Ping of the Death](https://capec.mitre.org/data/definitions/147.html) _(Severity: Medium)_
- [CAPEC-227 — Sustained Client Engagement](https://capec.mitre.org/data/definitions/227.html)
- [CAPEC-492 — Regular Expression Exponential Blowup](https://capec.mitre.org/data/definitions/492.html)

## ATT&CK-Techniken

- [T1499 — Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499/)

## BSI-Hinweise (deutsch)

- [Kibana: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3575) — _BSI-Einstufung: mittel_
  Ein Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um seine Privilegien zu erhöhen, und um einen Denial of Service Angriff durchzuführen.

## Referenzen

- <https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-181/390685>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-94400) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
