CVE-2026-78586
EUVD-2026-7006402.09.2026, 15:17
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | kibana | 8.0.0 ≤ 𝑥 ≤ 8.19.15 | CNA |
| elastic | kibana | 9.0.0 ≤ 𝑥 ≤ 9.3.4 | CNA |
| elastic | kibana | 9.4.0 ≤ 𝑥 ≤ 9.4.1 | CNA |
Vulnerability Media Exposure