CVE-2026-72651
EUVD-2026-5827613.08.2026, 20:17
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | kibana | 8.0.0 ≤ 𝑥 ≤ 8.19.19 | CNA |
| elastic | kibana | 9.0.0 ≤ 𝑥 ≤ 9.4.4 | CNA |
Vulnerability Media Exposure