Description
Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation (CWE‑20) in Kibana allows an authenticated user to submit a specially crafted Fleet policy, and the lack of validation can trigger a denial of service that renders the Fleet agent, server, and policy management functionality unavailable.

Affected Systems

The flaw affects all Elastic Kibana deployments that host or use Fleet policies; specific version numbers are not disclosed, so administrators should verify whether their current Kibana and Fleet components run at a vulnerable state. The issue exists in any deployment that allows users with permission to create or edit Fleet policies.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as medium severity, while the EPSS estimate of less than 1 % indicates a very low probability of exploitation. The issue is not listed in the CISA KEV. The specific role is not identified, but it is inferred from the description that a successful exploitation results in loss of availability for the Fleet component, disrupting monitoring and compliance operations.

Generated by OpenCVE AI on July 21, 2026 at 13:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Kibana and related Fleet components to versions that include the 2026.45 security fix.
  • Restrict access to Fleet policy creation and editing to privileged administrators and remove unnecessary permissions for other users.
  • If an upgrade is not immediately possible, disable monitor for anomalous policy creation activity until the vulnerability can be patched.

Generated by OpenCVE AI on July 21, 2026 at 13:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.
Title Improper Input Validation in Kibana Leading to Denial of Service
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-01T17:25:08.241Z

Reserved: 2026-06-19T11:01:02.535Z

Link: CVE-2026-56151

cve-icon Vulnrichment

Updated: 2026-07-01T17:20:53.047Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:00:05Z

Weaknesses
  • CWE-20

    Improper Input Validation