Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.
{
"cna_assigner": "elastic",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56151.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "9.0.0"
},
{
"last_affected": "9.3.5"
},
{
"introduced": "8.0.0"
},
{
"last_affected": "8.19.16"
},
{
"introduced": "9.4.0"
},
{
"last_affected": "9.4.2"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-20"
]
}{
"cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.19.17"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.3.6"
},
{
"introduced": "9.4.0"
},
{
"fixed": "9.4.3"
}
],
"source": "CPE_RANGE"
}"2026-07-15T15:53:37Z"
[
{
"target": {
"function": "sendResponse",
"file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/action/TransportInferTrainedModelDeploymentAction.java"
},
"id": "CVE-2026-56151-08cd97ae",
"digest": {
"function_hash": "29441788254395633515098764324401556637",
"length": 129.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/elastic/elasticsearch/commit/1f1ab65304a7633cd6511a1fa2b65c914064e724"
},
{
"target": {
"function": "testMultipleInferencesTriggeringDownloadAndDeploy",
"file": "x-pack/plugin/inference/qa/inference-service-tests/src/javaRestTest/java/org/elasticsearch/xpack/inference/DefaultEndPointsIT.java"
},
"id": "CVE-2026-56151-12a7e5d0",
"digest": {
"function_hash": "40397406528957796250670637991145046939",
"length": 1215.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/elastic/elasticsearch/commit/1f1ab65304a7633cd6511a1fa2b65c914064e724"
},
{
"target": {
"file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/action/TransportInferTrainedModelDeploymentAction.java"
},
"id": "CVE-2026-56151-9497d348",
"digest": {
"line_hashes": [
"41841651195592930148736172086999723057",
"293921697622875590993476152838503875226",
"201880235236449890862874291613591026267",
"6931030598426457207818976607922096200"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/elastic/elasticsearch/commit/1f1ab65304a7633cd6511a1fa2b65c914064e724"
},
{
"target": {
"function": "orderedListener",
"file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/action/TransportInferTrainedModelDeploymentAction.java"
},
"id": "CVE-2026-56151-c905e504",
"digest": {
"function_hash": "111700266056805079076925351035754336236",
"length": 617.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/elastic/elasticsearch/commit/1f1ab65304a7633cd6511a1fa2b65c914064e724"
},
{
"target": {
"function": "isTransientMlInferenceIndexError",
"file": "x-pack/plugin/inference/qa/inference-service-tests/src/javaRestTest/java/org/elasticsearch/xpack/inference/DefaultEndPointsIT.java"
},
"id": "CVE-2026-56151-d0d4b7fe",
"digest": {
"function_hash": "241575066176641808023110688533211015903",
"length": 304.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/elastic/elasticsearch/commit/1f1ab65304a7633cd6511a1fa2b65c914064e724"
},
{
"target": {
"file": "x-pack/plugin/inference/qa/inference-service-tests/src/javaRestTest/java/org/elasticsearch/xpack/inference/DefaultEndPointsIT.java"
},
"id": "CVE-2026-56151-df7c16bd",
"digest": {
"line_hashes": [
"330219953685486924298274755298237131959",
"166130015368858971406942022203579193789",
"337783925376695354837115980903317907964",
"150307750804902916410080975624959271234",
"153686128340309626383324163697449261191",
"102390998186244914873872092038171582988",
"245399238348785213885479398615378861075",
"117288393288463401964532166318938367911",
"214417864609834662678204278855561442218",
"245186405744128472060288516088896897897",
"193955595797424284137841368521614573857",
"9647211314265521622759035767770903218",
"243344772398150740875004430653142675275",
"83851240527543313267635888024470475211",
"78688963017947431333142322875487224392",
"168491302531714645767248205696815253686",
"125236309399044997400000281087699158995",
"132990391482460805336000105640402572742",
"291348162790534244772418497244911726327",
"132486071438518517437423506955922898453",
"80619291182477827634854396748823757331",
"33159264791753487181784553336347152862",
"153991559771436669268470682107481448841",
"191167260007516084674438259537540611494",
"239146445380549411566847675773548075115",
"14521978852238339045381558265113290694",
"178376481549476433071831563883359506428",
"116339813896664306671512025576166697825",
"229146779753699802054265479874943240634",
"46396995878082220991355606291219984101",
"167806518901712329362075522321398192931",
"28524417813964392607409780957224371900",
"10001939122652558884071231692076084665",
"311660342762049221221006871122406265296",
"105605360463024014740596183169296519056",
"248006774222241606148249795085412743613",
"273828121698775569320936307150012678626",
"146526953548968729068794463901905005369",
"309740307253372276004399670213634983671",
"232140615438285489033187652382509802494"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/elastic/elasticsearch/commit/1f1ab65304a7633cd6511a1fa2b65c914064e724"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56151.json"
{
"cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.19.17"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.3.6"
},
{
"introduced": "9.4.0"
},
{
"fixed": "9.4.3"
}
],
"source": "CPE_RANGE"
}