CVE-2026-0543
MEDIUM EPSS 28.9%
Published Jan 13, 20265mo ago · Modified Jun 17, 20261w ago
6.5 CVSS 3.1
Published Jan 13, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago
Description
Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector actions. The application attempts to process specially crafted email format, resulting in complete service unavailability for all users until manual restart is performed.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
28.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 2
CWE-20 Improper Input Validation Validation
CWE-770
Affected Products 4
References 1
- discuss.elastic.co https://discuss.elastic.co/t/kibana-8-19-10-9-1-10-9-2-4-security-update-esa-2026-08/384523
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.