CVE-2026-26935

Source
https://cve.org/CVERecord?id=CVE-2026-26935
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26935.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26935
Aliases
Downstream
Published
2026-02-26T17:05:16.619Z
Modified
2026-07-22T03:08:47.771317Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Improper Input Validation in Kibana Leading to Denial of Service
Details

Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "9.3.0"
                },
                {
                    "last_affected": "9.3.0"
                },
                {
                    "introduced": "8.4.0"
                },
                {
                    "last_affected": "8.19.11"
                },
                {
                    "introduced": "9.0.0"
                },
                {
                    "last_affected": "9.2.5"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-20"
    ],
    "cna_assigner": "elastic",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26935.json"
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:kibana:9.3.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "8.4.0"
        },
        {
            "fixed": "8.19.12"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.2.6"
        },
        {
            "introduced": "9.3.0"
        },
        {
            "last_affected": "9.3.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

9.*
9.3.0
v9.*
v9.3.0

Database specific

vanir_signatures_modified
"2026-07-22T03:08:47Z"
vanir_signatures
[
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1769.0,
            "function_hash": "9475014608979432872899083491102618214"
        },
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/b6e59ddaac5fc0c537d10132b2a1d5511ff8b1b5",
        "id": "CVE-2026-26935-23fdb02b",
        "target": {
            "function": "setupTwoClusters",
            "file": "x-pack/plugin/async-search/src/internalClusterTest/java/org/elasticsearch/xpack/search/CrossClusterAsyncSearchIT.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 958.0,
            "function_hash": "133451266018049555307972036747567205009"
        },
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
        "id": "CVE-2026-26935-44709111",
        "target": {
            "function": "syncBuiltInRoles",
            "file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "99199954569926070389755590458431893865",
                "313759815407396439660281880388391585122",
                "161102645631341755952971719744845873602",
                "4186666920153198943865131845554032355",
                "25468090382942619615217774101002806341",
                "313470468710636859297439073751114276151",
                "66718931484630687447592857125186493460",
                "24207978016146776076969048411650729239",
                "112550863571627868281286215194724888191",
                "257629881162110032714395006537365108931"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
        "id": "CVE-2026-26935-5f9a6220",
        "target": {
            "file": "x-pack/plugin/security/src/test/java/org/elasticsearch/test/SecurityIntegTestCase.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 72.0,
            "function_hash": "101359613813715596799098669389468934232"
        },
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
        "id": "CVE-2026-26935-7eb3b816",
        "target": {
            "function": "isSynchronizationInProgress",
            "file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "290299200757894439583714815578812186718",
                "169655607745751903048488107101990058530",
                "166338349120674636449812377777594551776"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
        "id": "CVE-2026-26935-8105e18c",
        "target": {
            "file": "x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizerTests.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "90084914409573906936379757312165312850",
                "121001556755942392594861396647986502913",
                "292860262293276780122791861456517913809",
                "189064083144340558976097844419482161337",
                "170036109944766967794168654275475188267",
                "168830856035572788271810376702342495",
                "7330473078786494025208501359190291269",
                "305654221205411734981376222466159728667",
                "173345538729514816951386971234382160660",
                "10277180135323892648044603022783539034",
                "93032768154059099699148095793739178027",
                "179625484193996379183604122731081889294",
                "132776780032578476164481467186876729006",
                "96140669458429765970392877159221345914",
                "174007588216295496161116936143898622479"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/b6e59ddaac5fc0c537d10132b2a1d5511ff8b1b5",
        "id": "CVE-2026-26935-b1b96921",
        "target": {
            "file": "x-pack/plugin/async-search/src/internalClusterTest/java/org/elasticsearch/xpack/search/CrossClusterAsyncSearchIT.java"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 583.0,
            "function_hash": "295080310505497328800607122027489892634"
        },
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
        "id": "CVE-2026-26935-c550a0a2",
        "target": {
            "function": "createSecurityIndexWithWaitForActiveShards",
            "file": "x-pack/plugin/security/src/test/java/org/elasticsearch/test/SecurityIntegTestCase.java"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "32062625129072983920028058538884317534",
                "36605260437218003236676516717207376115",
                "275251572708192921560642949692454487127",
                "69322198935595094552544202420825303013",
                "204189508549580167203700003970685711717",
                "200275780857157123884837014463936936819",
                "200238213166771762231720223821092393486",
                "77080184640576469221069162275208661231",
                "241552448252549514344260546419342732416",
                "184395862190808686364654112287864626160",
                "21262340089191862322692044690513150724",
                "303168300053863300365532002986515824616",
                "244043743419304174755717618883052239773",
                "198601726773172707137865878432157927310",
                "160173067990907518481820168210750268959",
                "118536611432114572498533366946624056113",
                "151188083657138064173439508561926804321",
                "66303635313521987898486263919309796562",
                "57127652560644982036908021870230098795",
                "169729806556418315554213555995148801320",
                "141277772941142071605729341553562846393",
                "215408178278593721394502038286795177004",
                "108358083274527797828220886478330682407",
                "135995618942555241468159231912235903527",
                "203013557821300387940709907789468421849",
                "80140506738272190341199483727436797382",
                "317723253769294839897187586336466383329",
                "280291953243866521885009154568627033710",
                "59988699721419414186936302902640832220",
                "49607341567707384950739807477900815537",
                "146678715625423207459312251605852192704",
                "261672105894779227279495728143227053252",
                "2057074736663939076853955293574438681",
                "105131071792840334483021920478890716067",
                "276622381611640845305936267226422248145",
                "335070780292288339104560083098573027458",
                "79046161274681637502415961148099472733",
                "245256323743556361925328426612049245288",
                "106491649802133929311570607434105379098",
                "31826412590017207828168230672741708725",
                "235850409320295939375720298931624755438"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/840cd2a58b052d1632219ee0b8dcc0f364226287",
        "id": "CVE-2026-26935-dca7c99a",
        "target": {
            "file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/support/QueryableBuiltInRolesSynchronizer.java"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26935.json"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:kibana:9.3.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "8.4.0"
        },
        {
            "fixed": "8.19.12"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.2.6"
        },
        {
            "introduced": "9.3.0"
        },
        {
            "last_affected": "9.3.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

9.*
9.3.0
v9.*
v9.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26935.json"