Description
Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of Improper Input Validation (CWE-20) in Elastic Kibana that allows an authenticated user to submit a specially crafted Fleet policy. The lack of validation can lead to a denial of service, rendering the Fleet agent, server, and policy management features unavailable. The attack can be carried out simply by creating or editing a policy through the Kibana interface without further privileges beyond normal Fleet policy authorship. The resulting loss of availability undermines monitoring, logging, and compliance workflows that rely on Fleet.

Affected Systems

The flaw affects Elastic Kibana and its integrated Fleet components. Specific version numbers are not disclosed in the advisory, so administrators should verify whether their current Kibana and Fleet installations are running a vulnerable state. The problem exists in deployments that allow policy creation and editing via Kibana and do not enforce proper input validation on the received policy data.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as medium severity, while the EPSS estimate of less than 1 % indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need authenticated access to Fleet policy creation and editing functions; once achieved, they can trigger a denial of service against Fleet components, disrupting monitoring and compliance operations.

Generated by OpenCVE AI on August 1, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Kibana and related Fleet components to the 2026.45 security fix.
  • Restrict access to Fleet policy creation and editing to privileged administrators, removing unnecessary permissions from other users.
  • If an upgrade is not immediately possible, disable Fleet policy creation until the vulnerability can be patched.

Generated by OpenCVE AI on August 1, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.
Title Improper Input Validation in Kibana Leading to Denial of Service
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-01T17:25:08.241Z

Reserved: 2026-06-19T11:01:02.535Z

Link: CVE-2026-56151

cve-icon Vulnrichment

Updated: 2026-07-01T17:20:53.047Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-01T17:16:37.167

Modified: 2026-07-02T16:09:39.207

Link: CVE-2026-56151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T23:00:05Z

Weaknesses
  • CWE-20

    Improper Input Validation