Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector actions. The application attempts to process specially crafted email format, resulting in complete service unavailability for all users until manual restart is performed.
2026-01-13T21:15:51.170
2026-01-22T20:04:20.370
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | elastic | kibana | ≤ 7.17.29 | Yes |
| Application | elastic | kibana | < 8.19.0 | Yes |
| Application | elastic | kibana | < 9.1.10 | Yes |
| Application | elastic | kibana | < 9.2.4 | Yes |