Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector actions. The application attempts to process specially crafted email format, resulting in complete service unavailability for all users until manual restart is performed.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector actions. The application attempts to process specially crafted email format, resulting in complete service unavailability for all users until manual restart is performed. | |
| Title | Improper Input Validation in Kibana Email Connector Leading to Excessive Allocation | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-01-13T21:25:59.853Z
Reserved: 2025-12-31T12:02:48.756Z
Link: CVE-2026-0543
Updated: 2026-01-13T21:25:53.582Z
Status : Received
Published: 2026-01-13T21:15:51.170
Modified: 2026-01-13T21:15:51.170
Link: CVE-2026-0543
No data.
OpenCVE Enrichment
No data.