Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value that causes excessive resource consumption, which may render Kibana unavailable.
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an authenticated user to send a request with an oversized input to Kibana’s Entity Analytics endpoints, causing the system to allocate more resources than it can handle. The resulting excessive consumption can make Kibana unavailable, effectively denying service to legitimate users. The weakness is a classic example of resource exhaustion (CWE‑770).

Affected Systems

Elastic Kibana is affected. No specific version information is provided.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1 % suggests a low current likelihood of exploitation. Although the vulnerability is not listed in the CISA KEV catalog, it remains a concern for environments where users have authenticated access to the Analytics endpoints. An attacker with valid credentials can trigger the denial of service by crafting an oversized payload, which makes this risk significant for systems that rely on high availability of Kibana.

Generated by OpenCVE AI on July 30, 2026 at 16:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Elastic Kibana to the latest version that includes the vendor‑supplied fix for resource exhaustion in Entity Analytics endpoints.
  • Configure container or host resource limits and enable request throttling for the Kibana process to prevent excessive memory or CPU consumption.
  • Restrict or remove access to the Entity Analytics endpoints for untrusted users, or disable the feature entirely if not required.

Generated by OpenCVE AI on July 30, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value that causes excessive resource consumption, which may render Kibana unavailable.
Title Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-22T18:25:52.607Z

Reserved: 2026-04-27T10:14:34.318Z

Link: CVE-2026-42397

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:53.210Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:45:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling