CVE-2026-72653
EUVD-2026-5827713.08.2026, 20:17
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. Kibana becomes unresponsive for all users and does not recover without manual intervention.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 8.12.0 ≤ 𝑥 < 8.19.19 |
| elastic | kibana | 9.0.0 ≤ 𝑥 < 9.3.8 |
| elastic | kibana | 9.4.0 ≤ 𝑥 < 9.4.4 |
𝑥
= Vulnerable software versions