CVE-2026-0528: Elastic Kibana
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.
Affected products
- Elastic Kibana: from 7.0.0, before 7.17.29 (fixed in 7.17.29); from 8.0.0, before 8.19.10 (fixed in 8.19.10); from 9.0.0, before 9.1.10 (fixed in 9.1.10); from 9.2.0, before 9.2.4 (fixed in 9.2.4)
Published 2026-01-13. Last modified 2026-06-17.