Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "9.3.0"
},
{
"last_affected": "9.3.0"
},
{
"introduced": "8.4.0"
},
{
"last_affected": "8.19.11"
},
{
"introduced": "9.0.0"
},
{
"last_affected": "9.2.5"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-20"
],
"cna_assigner": "elastic",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26935.json"
}{
"cpe": [
"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"cpe:2.3:a:elastic:kibana:9.3.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "8.4.0"
},
{
"fixed": "8.19.12"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.2.6"
},
{
"introduced": "9.3.0"
},
{
"last_affected": "9.3.0"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}"2026-07-22T03:08:47Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1769.0,
"function_hash": "9475014608979432872899083491102618214"
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/b6e59ddaac5fc0c537d10132b2a1d5511ff8b1b5",
"id": "CVE-2026-26935-23fdb02b",
"target": {
"function": "setupTwoClusters",
"file": "x-pack/plugin/async-search/src/internalClusterTest/java/org/elasticsearch/xpack/search/CrossClusterAsyncSearchIT.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 958.0,
"function_hash": "133451266018049555307972036747567205009"
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
"id": "CVE-2026-26935-44709111",
"target": {
"function": "syncBuiltInRoles",
"file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"99199954569926070389755590458431893865",
"313759815407396439660281880388391585122",
"161102645631341755952971719744845873602",
"4186666920153198943865131845554032355",
"25468090382942619615217774101002806341",
"313470468710636859297439073751114276151",
"66718931484630687447592857125186493460",
"24207978016146776076969048411650729239",
"112550863571627868281286215194724888191",
"257629881162110032714395006537365108931"
]
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
"id": "CVE-2026-26935-5f9a6220",
"target": {
"file": "x-pack/plugin/security/src/test/java/org/elasticsearch/test/SecurityIntegTestCase.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 72.0,
"function_hash": "101359613813715596799098669389468934232"
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
"id": "CVE-2026-26935-7eb3b816",
"target": {
"function": "isSynchronizationInProgress",
"file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"290299200757894439583714815578812186718",
"169655607745751903048488107101990058530",
"166338349120674636449812377777594551776"
]
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
"id": "CVE-2026-26935-8105e18c",
"target": {
"file": "x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizerTests.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"90084914409573906936379757312165312850",
"121001556755942392594861396647986502913",
"292860262293276780122791861456517913809",
"189064083144340558976097844419482161337",
"170036109944766967794168654275475188267",
"168830856035572788271810376702342495",
"7330473078786494025208501359190291269",
"305654221205411734981376222466159728667",
"173345538729514816951386971234382160660",
"10277180135323892648044603022783539034",
"93032768154059099699148095793739178027",
"179625484193996379183604122731081889294",
"132776780032578476164481467186876729006",
"96140669458429765970392877159221345914",
"174007588216295496161116936143898622479"
]
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/b6e59ddaac5fc0c537d10132b2a1d5511ff8b1b5",
"id": "CVE-2026-26935-b1b96921",
"target": {
"file": "x-pack/plugin/async-search/src/internalClusterTest/java/org/elasticsearch/xpack/search/CrossClusterAsyncSearchIT.java"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 583.0,
"function_hash": "295080310505497328800607122027489892634"
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
"id": "CVE-2026-26935-c550a0a2",
"target": {
"function": "createSecurityIndexWithWaitForActiveShards",
"file": "x-pack/plugin/security/src/test/java/org/elasticsearch/test/SecurityIntegTestCase.java"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"32062625129072983920028058538884317534",
"36605260437218003236676516717207376115",
"275251572708192921560642949692454487127",
"69322198935595094552544202420825303013",
"204189508549580167203700003970685711717",
"200275780857157123884837014463936936819",
"200238213166771762231720223821092393486",
"77080184640576469221069162275208661231",
"241552448252549514344260546419342732416",
"184395862190808686364654112287864626160",
"21262340089191862322692044690513150724",
"303168300053863300365532002986515824616",
"244043743419304174755717618883052239773",
"198601726773172707137865878432157927310",
"160173067990907518481820168210750268959",
"118536611432114572498533366946624056113",
"151188083657138064173439508561926804321",
"66303635313521987898486263919309796562",
"57127652560644982036908021870230098795",
"169729806556418315554213555995148801320",
"141277772941142071605729341553562846393",
"215408178278593721394502038286795177004",
"108358083274527797828220886478330682407",
"135995618942555241468159231912235903527",
"203013557821300387940709907789468421849",
"80140506738272190341199483727436797382",
"317723253769294839897187586336466383329",
"280291953243866521885009154568627033710",
"59988699721419414186936302902640832220",
"49607341567707384950739807477900815537",
"146678715625423207459312251605852192704",
"261672105894779227279495728143227053252",
"2057074736663939076853955293574438681",
"105131071792840334483021920478890716067",
"276622381611640845305936267226422248145",
"335070780292288339104560083098573027458",
"79046161274681637502415961148099472733",
"245256323743556361925328426612049245288",
"106491649802133929311570607434105379098",
"31826412590017207828168230672741708725",
"235850409320295939375720298931624755438"
]
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
"id": "CVE-2026-26935-dca7c99a",
"target": {
"file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26935.json"
{
"cpe": [
"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"cpe:2.3:a:elastic:kibana:9.3.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "8.4.0"
},
{
"fixed": "8.19.12"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.2.6"
},
{
"introduced": "9.3.0"
},
{
"last_affected": "9.3.0"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}