CVE-2026-26940
Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows an authenticated user to send a specially crafted Timelion expression that overwrites internal series data properties with an excessively large quantity value.
Vendor
Product
CWE
Yayın Tarihi
2026-03-19 18:16:21
Güncelleme
2026-03-23 13:35:49
Source Identifier
security@elastic.co
KEV Date Added
-