Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk deletion request that causes excessive resource consumption, which may render Kibana unavailable.
{
"cwe_ids": [
"CWE-770"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49087.json",
"cna_assigner": "elastic",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "9.0.0"
},
{
"last_affected": "9.3.3"
},
{
"introduced": "8.0.0"
},
{
"last_affected": "8.19.14"
}
]
}
]
}"2026-07-21T23:25:23Z"
[
{
"signature_type": "Function",
"target": {
"file": "x-pack/plugin/esql/src/test/java/org/elasticsearch/xpack/esql/analysis/AnalyzerTests.java",
"function": "testPromqlQueryWithConflictingTsTypesMarksFieldUnsupported"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/69a3e6c50ebb57a1fdbf3f235be9f11061ac7d86",
"id": "CVE-2026-49087-0b400218",
"signature_version": "v1",
"digest": {
"function_hash": "84433789544010315812246774005552675939",
"length": 601.0
}
},
{
"signature_type": "Line",
"target": {
"file": "x-pack/plugin/esql/src/test/java/org/elasticsearch/xpack/esql/analysis/AnalyzerTests.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/69a3e6c50ebb57a1fdbf3f235be9f11061ac7d86",
"id": "CVE-2026-49087-53609d75",
"signature_version": "v1",
"digest": {
"line_hashes": [
"234163232951028422978085367395355015356",
"336324895495804197828852394756872939000",
"283658986481949763179231452461160578552",
"90983762437915623732177975884360609784",
"201530536742802531269305682045005216476",
"171852364269482810748858037036789861963",
"314462254603794552743574645931750044692",
"295350290235740750339653402330741971858",
"214199429833385077961909239085936134582",
"165345166082600797091855140208265768837",
"68922472427642386306783373118438221572"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49087.json"