{"id":"CVE-2026-49089","summary":"Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service","details":"Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana process to spend an unbounded amount of time evaluating it. An authenticated user with read-only privileges was able to send a single request that left Kibana unable to serve any user until the process was restarted.","aliases":["BIT-elk-2026-49089","BIT-kibana-2026-49089"],"modified":"2026-09-04T08:06:30.179563Z","published":"2026-08-13T19:08:07.007Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49089.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.0.0"},{"last_affected":"8.19.19"},{"introduced":"9.0.0"},{"last_affected":"9.4.4"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-8-19-20-9-4-5-security-update-esa-2026-137/389511"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49089.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49089"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"91f5381ece296ddc32b554f997269478b9224af8"},{"introduced":"112859b85d50de2a7e63f73c8fc70b99eea24291"},{"fixed":"adc1f04ffdd393d1977990338d5512c5eaf1ce94"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.19.20"},{"introduced":"9.0.0"},{"fixed":"9.4.5"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49089.json","vanir_signatures_modified":"2026-09-04T08:06:30Z","vanir_signatures":[{"source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighterTests.java"},"deprecated":false,"digest":{"line_hashes":["283190670438501987514727838726815920477","139872482520600089094968553951135983484","244928736363048457427079246025589015191"],"threshold":0.9},"id":"CVE-2026-49089-15fc2a3d","signature_type":"Line","signature_version":"v1"},{"target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java","function":"setupParser"},"deprecated":false,"digest":{"length":2369,"function_hash":"35973537492193988444530376691395407843"},"id":"CVE-2026-49089-3749bff4","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94"},{"signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java"},"deprecated":false,"digest":{"line_hashes":["114508176030696626539066047296433779214","43384607500169746049581282043376952148","283563727296098110195444588655154165811","277031765205288332698033581440269116720","187407052376657667672985622362187421922","90126549817761157374395826113896432271","62431126033836515299954878706677890458","276372619117036678140958072933552714348","34204804071724460000309539643270206424","178874689487166837173458238589286447776"],"threshold":0.9},"id":"CVE-2026-49089-56785d56","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java","function":"highlight"},"deprecated":false,"digest":{"function_hash":"74600334261879604741521313242640339568","length":4662},"id":"CVE-2026-49089-687797ed","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java","function":"getFieldType"},"deprecated":false,"digest":{"function_hash":"10160088286724545746756661846724288313","length":176},"id":"CVE-2026-49089-6e669937"},{"target":{"file":"server/src/main/java/org/elasticsearch/rest/action/search/SearchCapabilities.java"},"deprecated":false,"digest":{"line_hashes":["130192812032915568189929366428112074279","338587668112843751875004607897056457244","311636223832287298418351940618914661904","14559433973571236327103093772803942734","81766092491860980139880041074416541030","83778004218823664808743686188872036723","217672029278899031516016760140755058444"],"threshold":0.9},"id":"CVE-2026-49089-9734acfc","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94"},{"deprecated":false,"digest":{"line_hashes":["243868588130949656791143692081236563864","311505216586199373294314499230294889565","23300629379259170631342652985157100415","99779525804820300359777388439313924719","124392759507223488964887386448798184793","57056074566821104672192600168236166604","183428232184500482658775793061523078930"],"threshold":0.9},"id":"CVE-2026-49089-bd63b83e","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java"}},{"target":{"file":"server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java"},"deprecated":false,"digest":{"line_hashes":["122639132757664986803138175691671001655","335892283999867396276535502941166644649","252845685254806679929754126735709659653","70459544080609156892578956654685198979","288350301639674802567568120843372854348","128879439556083118790804565740578695567","183568503689704087885138164738553210791","315988264130765396628199666193426980549","110105306531665817097053229432225710351","108886619290626151118397149603734671098","68900764452827513161409585113073530589","109699481272201296627752008736891181922","89552474233322494405147063649180198152","243794874480578150177830085733756836217","128936352400535787295390066296206280301","168193967744077208144892951303807415035","32485489507345202777470620624306770167","82468793747458534960176489784612968344","95431536162858288727547312167888083055","79895802567313409968279279144916310561","109983373614664327492018760324106301607","254164139643632659290414288579740637195","218911482828271878345863242741149783938","290149128642774742559654272690374710990","129649976829885946269329561068451864187","271521553609249011929656203339955131993","116967678018103273313850160203491775016","34507466461561024444180968955125864688","149539466270008484339757108260134471872","241540141246676079432554907112288153733","247281622777097759942516432384261889326","8682106367820934505412234917026602498","258599880353756871245323998211345504441","140682565192181975671989624265695960587","100268892565605616091333444189761449681","214950598829781998119271592022997186976","200550104524719405385075838124186899375","313720121068230248463194804287647092807","188167255630204728049901172366742944889","197051329735330186721065881872811534640","246392715163119707808625433035684232434","127945619089996738346525337879859203179","136702270964155933380398036066653195170"],"threshold":0.9},"id":"CVE-2026-49089-ca3692e7","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94"},{"deprecated":false,"digest":{"function_hash":"186492591955110081095185334864085897708","length":674},"id":"CVE-2026-49089-dc0a4f96","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java","function":"build"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java","function":"testBuildSearchContextHighlight"},"deprecated":false,"digest":{"function_hash":"50460798663850937323875144151113267593","length":3586},"id":"CVE-2026-49089-e5c86fee"},{"deprecated":false,"digest":{"line_hashes":["250502453778712768962053518703255093608","293745187741608286289486472330502044902","92285933861987769382932879499624280339","48848052402887098574079705828368727963","180954780310110417851376237840132855867","265701660666103015958674140349152633739","219483656979539974598819100907886798376"],"threshold":0.9},"id":"CVE-2026-49089-f6f0ec86","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94","target":{"file":"server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java"}}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"57ca5e139a33dd2eed927ce98d8231a1f217cd15"},{"fixed":"4036be744384423f261fcf74b1b99fd4d044dc97"},{"introduced":"504d6bfa94cca17fabb76e06152c30c4f0c3efdd"},{"fixed":"bc80ff828630b51dd591207f43a54ea5ebf53270"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.19.20"},{"introduced":"9.0.0"},{"fixed":"9.4.5"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49089.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}